Recent reports reveal Apple’s iCloud Private Relay is leaking users’ real IP addresses

Recent reports reveal Apple’s iCloud Private Relay is leaking users’ real IP addresses

Researchers have discovered that Apple’s iCloud Private Relay, an iCloud+ feature designed to hide users’ IP addresses while browsing in Safari, can be bypassed through a Passkey WebAuthn request, potentially exposing the user’s real IP address.

The issue occurs because Passkey credential requests operate outside Safari’s standard browsing connection, so their network traffic is not routed through Private Relay. A website can initiate one of these requests and use the resulting connection to identify the visitor’s real IP address, despite the user browsing through Safari with the privacy feature enabled.

Researchers Talal Haj Bakry and Tommy Mysk traced the leak to three WebKit features, meaning some third party and Tor based browsers using WebKit’s proxy relay may also be affected. They did not privately report the issue to Apple, citing previous delays and disagreements over the impact of reported vulnerabilities, but published a proof of concept website that lets users check whether Private Relay is exposing their real IP address. Its also worth mentioning that Mysk and his colleagues also develop Psylo, a privacy focused browser that now includes mitigations against this type of leak.

Apple has not commented or provided a timeline for a fix, but this follows another iCloud related privacy flaw disclosed last month, when researchers found that the Hide My Email feature could actually expose users’ real email addresses.

by Mauricio B. Holguin

Add as a preferred source on Google
No comments so far, maybe you want to be first?
Gu