iCloud Private Relay IP Leak: Three WebKit Flaws Expose Real User IP Addresses

iCloud Private Relay IP leak via three WebKit vulnerabilities DNS prefetch WebAuthn WebTransport bypassing proxy on iOS iPadOS macOS Safari and third-party browsers

A feature designed to shield users from surveillance on the internet has been found capable of disclosing their genuine location – a fundamental contradiction embedded within Apple’s iCloud Private Relay. The service, available to iCloud+ subscribers, routes Safari traffic through two independent relay nodes in sequence, ensuring that neither node – including Apple itself – can simultaneously observe both the source of a request and the websites being visited.

Researchers Talal Haj Bakry and Tommy Mysk have identified the vulnerability. As detailed in their technical analysis of the WebKit proxy bypass and iCloud Private Relay IP leak, the root cause lies in three distinct functions of the WebKit browser engine – the engine that powers Safari and, by extension, every third-party browser on iOS and iPadOS, including Chrome, Edge, Firefox, and Brave.

The Three Leaking Mechanisms

Each of the three implicated WebKit functions transmits a portion of data directly from the device, circumventing the configured proxy entirely. In each case, the user’s real IP address escapes the Private Relay tunnel and becomes visible to external parties.

DNS Prefetching

WebKit’s DNS prefetch mechanism resolves domain names in anticipation of future requests. This resolution occurs outside the proxy channel, exposing the device’s originating IP address to the DNS resolver before the Private Relay infrastructure can intercept the traffic.

WebAuthn Origin Validation

The most consequential of the three vectors involves WebAuthn – the industry standard underpinning passkey authentication. During the origin verification step that WebAuthn performs, a network request is dispatched directly from the device, bypassing the proxy. Critically, this behavior does not require the user to initiate a passkey login or perform any deliberate action. Any website that supports WebAuthn can intentionally exploit this implementation detail to associate a browsing session with the user’s real IP address – passively and without consent.

WebTransport

The WebTransport protocol, used for low-latency bidirectional communication, similarly routes certain connection establishment traffic outside the proxy boundary, leaking the device’s true address.

Scope: iOS, iPadOS, and macOS

The vulnerability is not confined to mobile devices. It affects iOS, iPadOS, and macOS wherever WebKit-based browsers employ the engine’s native proxy handling mechanisms. The researchers have published a testing tool at leaks.psylo.app, where users can verify whether their real IP address is exposed while Private Relay is active.

Mysk has noted that the leak does not manifest universally across all browsers. The desktop version of Chrome, for instance, is not affected by the issue. Establishing an additional VPN connection on top of Private Relay also reduces the risk of exposure.

Apple’s Response and Prior Incidents

Apple has confirmed to 404 Media that it is reviewing the submitted report. No official statement or timeline for a fix has been issued at the time of writing.

This is not the first time Apple’s privacy infrastructure has harbored an undisclosed leak. The Hide My Email service previously contained a similar flaw that could expose a user’s genuine email address. Shortly after Private Relay’s launch in 2021, researchers at FingerprintJS discovered a separate IP address leak occurring through WebRTC.

Mitigations Until a Patch Arrives

Until Apple issues a formal resolution, users can reduce their exposure by layering an additional VPN connection on top of iCloud Private Relay. Users on Apple devices should also exercise particular caution when interacting with websites that prompt passkey sign-in via WebAuthn, as those sites represent the most passive and consequential exploitation path currently available to a motivated adversary.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply