VMTech
Discuss a project

WebKit proxy bypasses may expose iCloud Private Relay IP addresses

WebKit proxy bypasses may expose iCloud Private Relay IP addresses

WebKit features can bypass iCloud Private Relay

Security researchers Talal Haj Bakry and Tommy Mysk have disclosed an issue that can expose the real IP address of people using Apple’s iCloud Private Relay. They identified three WebKit features—DNS prefetching, WebAuthn Related Origin Requests and WebTransport—that can bypass a browser’s configured proxy and send traffic directly from the device.

iCloud Private Relay, introduced with iOS 15 and included with iCloud+, uses a dual-hop design for Safari traffic. Apple describes the architecture as ensuring that no single party, including Apple, can identify both the origin of a request and the websites a user visits. The reported WebKit behaviour creates paths outside that intended proxy route.

Three direct network paths

DNS prefetching resolves hostnames through the device’s ordinary DNS route rather than through the browser proxy. WebAuthn Related Origin Requests can cause the operating system credential service to retrieve a validation file directly from the device. WebTransport can establish a direct HTTP/3 connection, also bypassing the proxy configuration.

WebKit is Safari’s browser engine and is also used by third-party browsers on iOS and iPadOS, including Google Chrome, Microsoft Edge, Mozilla Firefox and Brave. The researchers said the behaviour also affects macOS and other WebKit-based browsers that use WebKit proxy configuration APIs.

Passkey support can create an IP disclosure path

WebAuthn is the standard used for passkey sign-in. Mysk said a website that deliberately configures WebAuthn in the relevant way can reveal the browser’s real IP address and associate it with the active browsing session. The reported technique does not require user interaction or the use of a passkey.

The researchers published a proof-of-concept site, leaks.psylo[.]app, which separates ordinary HTTPS traffic from possible IP leaks. They noted that the result is not universal: desktop Chrome is not affected in their example, and connecting through a VPN mitigates the reported leaks. Apple told 404 Media that it is investigating the report.

Privacy controls need layered validation

The finding follows past privacy concerns around Apple services, including a WebRTC-based iCloud Private Relay IP leak highlighted after the feature’s 2021 launch. It also sits alongside browser credential and critical vulnerability exposure paths, where browser-stored credentials and critical vulnerabilities illustrated how endpoint and browser controls can create unexpected exposure paths.

For businesses, the practical implication is to avoid treating Private Relay as a standalone anonymity guarantee: review WebKit-dependent workflows, validate outbound traffic paths, and use a VPN where protection of the device IP address is a formal requirement.

#icloudprivacy#webkitsecurity#networksecurity#browsersecurity
Open analytics
On the site 0 views
min read 3 06.08.2026
Instagram

WebKit proxy bypasses may expose iCloud Private Relay IP addresses

Open the post on Instagram ↗