TechNewsReel
Live

WebKit Flaws Allow Websites to Bypass Apple's iCloud Private Relay

Security researchers discovered three engine-level vulnerabilities that expose users' real IP addresses despite privacy settings.

TechNewsReel Newsroom · August 5, 2026

Security researchers Tommy Mysk and Talal Haj Bakry have identified a series of flaws in Apple's WebKit engine that allow websites to bypass iCloud Private Relay. The vulnerability enables sites to uncover a user's real IP address, undermining a primary privacy feature for iCloud+ subscribers.

The leak is triggered by three specific WebKit features that send traffic directly from the device, bypassing the proxy path. According to the researchers, DNS prefetching reveals the user's DNS servers, while WebTransport exposes the real IP via a direct HTTP/3 connection. Additionally, WebAuthn Related Origin Requests reveal the IP address through the operating system's credential service. To demonstrate these vulnerabilities, Mysk and Haj Bakry launched a proof-of-concept website, leaks.psylo.app, where users can verify if their data is leaking.

The Architecture Gap

iCloud Private Relay is an opt-in service designed to mask IP addresses and DNS queries from websites visited via Safari. It employs a two-hop relay system to ensure that no single entity knows both the user's identity and their destination. However, because Private Relay operates at the browser and application level rather than the system level, it is susceptible to leaks if specific engine features bypass the proxy.

In contrast, system-level VPNs remain unaffected by these flaws. This is because VPNs tunnel all network traffic for the entire device, whereas Private Relay is limited to proxying Safari web traffic. This distinction highlights a fundamental difference in how the two technologies handle data routing and privacy.

Systemic Privacy Risks

This vulnerability is particularly significant because WebKit is the mandatory engine for all browsers on iOS. Consequently, the flaw impacts a wide range of privacy-focused tools, including the Psylo browser and Tor browsers on the platform. By exposing the real IP of users who rely on these tools for anonymity, the flaw represents a systemic weakness in Apple's privacy architecture.

Future Outlook

Despite the severity of the leak, the researchers stated they did not report the issue to Apple. Tommy Mysk noted that past experiences with the company involved months of delays, inconsistent communication, and instances where Apple denied the impact of reported issues. It remains to be seen if Apple will issue a patch for these WebKit features or if users will need to rely on system-wide VPNs for guaranteed IP masking.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.