Breaking
SecurityDeveloping Story

WebKit Flaws Expose Apple Private Relay

Security researchers uncovered vulnerabilities in WebKit that allow websites to bypass Apple's Private Relay and view IP addresses.

··2 hours ago·2 min read
Smartphone displaying firefox browser app with logo.
Photo by Zulfugar Karimov on Unsplash

According to reporting from TechCrunch, vulnerabilities discovered in Apple's web browser infrastructure could allow web servers to discover the real IP addresses of users relying on iCloud Private Relay. The system, intended to mask user locations and browsing activity in Safari, can allegedly be circumvented due to underlying issues within WebKit.

WebKit Engine Vulnerabilities Bypassing Safari Privacy

Security researchers in a blog post disclosed that Apple's IP-masking mechanism contains structural flaws that expose user identities. TechCrunch reported that the issue was initially uncovered by researchers Talal Haj Bakry and Tommy Mysk.

The core functionality of Private Relay is offered as an opt-in feature specifically for iCloud+ subscribers. It aims to conceal an individual's IP address while they browse the web, preventing third parties from building profiles based on network location.

Flaws Traced to Three WebKit Features

The researchers noted that the vulnerability does not stem from the network relays themselves, but rather from three features inside WebKit. WebKit serves as the underlying browser engine that powers Safari and all web browsers running on iOS.

Because these flaws reside directly in the WebKit codebase, the mechanism designed to proxy network requests can be completely bypassed by target websites under specific technical conditions.

Scope Limited to Safari and iOS

Unlike a traditional Virtual Private Network (VPN), which secures network traffic across an entire operating system at the system level, Apple's implementation operates within narrower technical boundaries. Private Relay functions exclusively while browsing the internet through Safari.

As a result, applications outside the browser context rely on standard network connections, while Safari traffic remains subject to the specific WebKit processing rules where the IP leak occurs.

Verification Confirms Real IP Exposure Online

The researchers set up a website designed to test whether an active Private Relay connection effectively masks user information. In testing conducted on Tuesday, TechCrunch confirmed that visiting the site successfully revealed their actual IP address despite having Private Relay enabled.

The existence of the vulnerability was first reported by 404 Media before further details regarding the WebKit flaws were published broadly by the research team.

Researchers Bypass Apple Vulnerability Reporting Channels

Rather than submitting their findings through Apple's standard disclosure processes, the researchers chose to publish their work publicly. In a statement shared on X, Mysk explained the rationale behind withholding the report from the technology giant.

“our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely.”

— Tommy Mysk, security researcher

Apple did not immediately respond to requests for comment regarding the researchers' findings or the reported WebKit vulnerabilities.

Alternative Browser Implements Custom Defensive Mitigations

In addition to documenting the flaws, Mysk and his team develop a specialized private browser named Psylo. The developers confirmed that they implemented mitigations within Psylo designed to prevent real IP address leaks when navigating the web.

For everyday users relying on standard Safari configurations and iCloud+ protections, the disclosure suggests that browser-level privacy features may not offer complete isolation from tracking until underlying engine fixes are deployed across WebKit.

#apple#private relay#webkit#privacy#ios

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted with AI assistance from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our AI Policy →

← Back to all stories