Security researchers Talal Haj Bakry and Tommy Mysk have identified three WebKit features that cause iCloud Private Relay leaks. This vulnerability allows websites to potentially uncover a user's real IP address, undermining the privacy protections intended for Safari users on iOS and macOS devices. The flaw stems from how certain browser technologies handle network requests outside the relay's proxy configuration.
Which WebKit features cause the leaks?
The identified WebKit features include DNS prefetching, WebAuthn, and WebTransport. These technologies can inadvertently establish network connections that bypass the proxy configuration of iCloud Private Relay. While DNS prefetching can reveal network information, WebAuthn and WebTransport requests can expose a user's actual IP address to destination servers, effectively circumventing the privacy measures Apple designed to mask user location and identity during web browsing.
How can users protect their privacy?
While these specific WebKit vulnerabilities affect Safari and related browsers, researchers note that system-level VPNs are not susceptible to these leaks. Because VPNs tunnel all network traffic at the operating system level rather than relying on browser-level proxy configurations, they remain an effective alternative for users concerned about IP exposure. Users should remain aware that while Private Relay is a valuable tool, it is not a complete shield against all forms of tracking.