Announcements
We ıntegrate ınformatıon ın lıfe

  • DOLAR
  • EURO
  • ALTIN
  • BIST
IP Leak Detected in iCloud!

IP Leak Detected in iCloud!

A security vulnerability detected in Apple’s iCloud Private Relay feature causes users’ real IP addresses to be leaked.

Apple’s iCloud Private Relay feature, offered as part of its iCloud+ subscriptions, is failing to deliver the expected performance in hiding users’ IP addresses. Security researchers Tommy Mysk and Talal Haj Bakry have revealed that this layer of concealment reveals real IP addresses in certain situations.

The leak occurs particularly on websites that use, or appear to use, passkey technology. While iCloud Private Relay aims to mask IP and DNS information during browsing via Safari, a vulnerability in the system’s operation disables this concealment.

Technical Details and Effects of the Leak

Passkey technology, which uses the WebAuthn standard, stores the private key directly within the device instead of the Safari browser. WebKit delegates these authentication processes to the operating system’s own credential service, and in this process, the HTTPS request is made directly from the device.

These requests, initiated by the operating system’s credential service, do not bypass iCloud Private Relay’s proxy path and therefore cannot exploit the system’s defenses. This allows malicious websites to identify a user’s real IP address without any random user interaction or a visible warning window.

Researchers state that they have discovered two more features in the WebKit infrastructure that leak IP addresses and DNS information. The DNS prefetching feature introduced with iOS 26 reveals the user’s real DNS servers, while the WebTransport feature added with iOS 26.4 can also lead to IP address leaks.

Apple’s Approach to the Issue and Recommendations for Users

Apple has stated that it is investigating reports on the matter and is aware of the problem. Mysk and Haj Bakry have created a dedicated website where users can test whether iCloud Private Relay is leaking information on their own devices.

Because the problem stems directly from the WebKit infrastructure, not only Safari but also some third-party browsers using this infrastructure are facing the same risk. Until Apple releases an update to fix this security vulnerability, users who want a higher level of protection are advised to use VPN services.

What do you think about this security vulnerability, will you continue to trust iCloud Private Relay?

Social Media Share:

TOGETHER FOR A LOOK

Can you share with us your comment?