The researchers demonstrated the exploit through a dedicated testing site, which successfully identified real IP addresses during verification tests. According to the findings, the leak originates from three specific features within WebKit, the underlying browser engine powering all iOS web browsers. Unlike a system-wide VPN, Private Relay operates exclusively within Safari, leaving gaps in how network requests are handled.
Apple Private Relay Vulnerability Exposes User IP Addresses
Security researchers Talal Haj Bakry and Tommy Mysk have uncovered significant flaws in Apple’s Private Relay, revealing that the feature intended to anonymize Safari browsing habits can be circumvented. The vulnerability allows websites to bypass the protective layer and access a user’s actual IP address despite an active iCloud+ subscription.

Bakry and Mysk opted to bypass Apple’s formal disclosure process entirely. Citing past frustrations with the company’s security reporting channels, they alleged a history of delayed responses and denials regarding the severity of previously reported flaws. Apple has not yet provided a statement regarding these claims. Meanwhile, the researchers have already implemented patches within their own browser, Psylo, to block the specific WebKit behaviors that lead to these leaks.



Comments (0)
No comments yet. Be the first!