LIVE · cybersecurity feed
Live wire
vulnerability

Apple WebKit vulnerabilities reveal your IP address, despite Private Relay

Researchers have found three methods to bypass Apple's Private Relay which is supposed to shield users' IP addresses and location.

zeroday.news ·

Multiple mechanisms within Apple's WebKit browser engine have been identified that can bypass iCloud Private Relay and other browser-level proxy configurations, potentially revealing a user's true IP address and DNS information. The vulnerabilities, reported to Apple, affect Safari on both iOS and macOS, as well as any other iOS/macOS browser or application that relies on WebKit's proxy configuration for IP address concealment.

The issue stems from three specific WebKit features that initiate network requests outside of the engine's standard page loading path. Because iCloud Private Relay and similar proxies are implemented at the WebKit level and only apply to traffic within this normal path, they fail to intercept these specific requests.

One such mechanism is DNS prefetching, a feature designed to speed up browsing by resolving the IP addresses of links on a page before a user clicks them. Researchers found that in WebKit, these DNS lookups can bypass the configured proxy or relay, directly utilizing the system's default DNS stack. This exposes the DNS servers in use and, indirectly, the user's general location, even if the subsequent page load is routed through Private Relay.

Another bypass involves WebAuthn, the underlying standard for passkeys. When a website uses passkeys, WebAuthn may need to fetch a small file from the site's domain to verify the credential. On Apple platforms, this fetch is performed outside WebKit's proxied page-loading path, meaning it is not sent through Safari's proxy or Private Relay. Consequently, a website implementing passkeys can directly contact the user's device, revealing its true IP address despite the user's expectation of privacy.

The third identified vulnerability relates to WebTransport and similar technologies. WebTransport is an API that allows websites to establish low-latency, bidirectional connections to a server. In tests, these WebTransport connections were also initiated outside the proxied WebKit code path, creating an additional route for websites to receive direct traffic from the device, again exposing the user's real IP address instead of the expected relay or proxy IP.

These mechanisms are problematic from a user experience standpoint because they appear to be normal browser behavior and do not require any specialized or malicious tricks from a website to exploit.

While Apple has recently introduced a mechanism for non-WebKit browser engines on iOS, primarily due to regulatory pressures like the EU's Digital Markets Act, no major browser vendor has yet shipped a non-WebKit browser. Most are still in the prototype phase, indicating that the vast majority of iOS browsers continue to rely on the WebKit engine and are thus susceptible to these issues.

System-level VPNs, such as Malwarebytes VPN, are not affected by these WebKit vulnerabilities because they tunnel all of a device's network traffic at the operating system level, rather than relying on browser-specific proxy configurations. The researchers have reported their findings to Apple and anticipate that patches will be released by the fall.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-63077critical

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek.

security

Snowflake Hacker Pleads Guilty in US Court

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. The post Snowflake Hacker Pleads Guilty in US Court appeared first on SecurityWeek.

security

TeamPCP Traced Back to 2020 Cryptojacking Operation

Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020

breach

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from

ai

OWASP 2026 LLM Top 10: “The model will be fooled”

The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant, but the order shifted more than in past years below them: The 2025 and 2026 versions of OWASP 2026 LLM Top 10, compared (Source: OW

ai

OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack

It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence