WebKit Flaws Expose Apple Private Relay
Security researchers uncovered vulnerabilities in WebKit that allow websites to bypass Apple's Private Relay and view IP addresses.
According to reporting from TechCrunch, vulnerabilities discovered in Apple's web browser infrastructure could allow web servers to discover the real IP addresses of users relying on iCloud Private Relay. The system, intended to mask user locations and browsing activity in Safari, can allegedly be circumvented due to underlying issues within WebKit.
WebKit Engine Vulnerabilities Bypassing Safari Privacy
Security researchers in a blog post disclosed that Apple's IP-masking mechanism contains structural flaws that expose user identities. TechCrunch reported that the issue was initially uncovered by researchers Talal Haj Bakry and Tommy Mysk.
The core functionality of Private Relay is offered as an opt-in feature specifically for iCloud+ subscribers. It aims to conceal an individual's IP address while they browse the web, preventing third parties from building profiles based on network location.
Flaws Traced to Three WebKit Features
The researchers noted that the vulnerability does not stem from the network relays themselves, but rather from three features inside WebKit. WebKit serves as the underlying browser engine that powers Safari and all web browsers running on iOS.
Because these flaws reside directly in the WebKit codebase, the mechanism designed to proxy network requests can be completely bypassed by target websites under specific technical conditions.
Scope Limited to Safari and iOS
Unlike a traditional Virtual Private Network (VPN), which secures network traffic across an entire operating system at the system level, Apple's implementation operates within narrower technical boundaries. Private Relay functions exclusively while browsing the internet through Safari.
As a result, applications outside the browser context rely on standard network connections, while Safari traffic remains subject to the specific WebKit processing rules where the IP leak occurs.
Verification Confirms Real IP Exposure Online
The researchers set up a website designed to test whether an active Private Relay connection effectively masks user information. In testing conducted on Tuesday, TechCrunch confirmed that visiting the site successfully revealed their actual IP address despite having Private Relay enabled.
The existence of the vulnerability was first reported by 404 Media before further details regarding the WebKit flaws were published broadly by the research team.
Researchers Bypass Apple Vulnerability Reporting Channels
Rather than submitting their findings through Apple's standard disclosure processes, the researchers chose to publish their work publicly. In a statement shared on X, Mysk explained the rationale behind withholding the report from the technology giant.
“our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely.”
— Tommy Mysk, security researcher
Apple did not immediately respond to requests for comment regarding the researchers' findings or the reported WebKit vulnerabilities.
Alternative Browser Implements Custom Defensive Mitigations
In addition to documenting the flaws, Mysk and his team develop a specialized private browser named Psylo. The developers confirmed that they implemented mitigations within Psylo designed to prevent real IP address leaks when navigating the web.
For everyday users relying on standard Safari configurations and iCloud+ protections, the disclosure suggests that browser-level privacy features may not offer complete isolation from tracking until underlying engine fixes are deployed across WebKit.
Sources
- TechCrunch Original source
- in a blog post Also reporting
- set up a website Also reporting
- Private Relay Also reporting
- was first reported Also reporting
Continue Reading
Flowise Fixes Critical Root RCE Vulnerability
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
Flowise Patches Critical CSVAgent RCE Flaw
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
Candidate Arrested Over ALPR Camera Damage
A Tennessee congressional candidate faces felony vandalism charges after allegedly shooting automated license plate readers.