Apple Private Relay Bug Can Leak Your IP Address via WebKit
Security researchers find that Apple's Private Relay feature can leak your IP address due to a WebKit issue when using passkeys on iOS devices.
A newly discovered security vulnerability in Apple's WebKit browser engine compromises user anonymity by leaking real IP addresses when utilizing passkey logins. The flaw directly undermines Apple's iCloud+ Private Relay feature, which is designed to mask user identities and locations on Safari. Because the underlying WebKit engine powers all web browsers on iOS, this security loophole exposes users across multiple applications, including specialized privacy browsers, leaving individuals vulnerable to tracking despite active privacy settings.
The leak occurs specifically during the authentication process for passkeys, a modern password-free login standard. When a user logs into a website using a passkey, the device initiates an authentication request that bypasses the browser's standard traffic routing. Unlike a virtual private network (VPN) that secures all device data, Private Relay only shields standard web traffic within Safari. Consequently, this external authentication request bypasses the protective relay, exposing the user's true IP address directly to the destination server.
Apple introduced Private Relay as a premium privacy feature to prevent network providers and websites from tracking user browsing behavior. Simultaneously, the tech industry has heavily promoted passkeys as a highly secure, cryptographic alternative to traditional passwords. However, the integration of these two technologies relies on WebKit, the mandatory rendering engine for all iOS web browsers. This shared architecture means that even alternative browsers designed specifically for anonymity, such as Onion Browser, suffer from the same IP exposure.
Security analysts have already shared their findings and potential workarounds with the developers of alternative browsers and privacy networks. While Apple has acknowledged the reports and initiated an investigation into the WebKit vulnerability, history suggests a resolution may not arrive quickly. A similar privacy flaw involving iCloud's Hide My Email feature, which leaked actual email addresses instead of aliases, remained unresolved for a full year after its initial discovery before a patch was finally deployed.
This vulnerability carries significant consequences for users who rely on absolute anonymity, such as journalists, activists, and privacy advocates. By exposing the true IP address, the flaw defeats the core purpose of using privacy-centric browsers on mobile devices. The revelation also damages trust in Apple's marketing of iOS as a highly secure ecosystem, proving that even advanced privacy tools can fail due to overlooked system-level interactions.
Looking ahead, users seeking guaranteed anonymity on iOS devices must exercise caution when adopting passkeys until a permanent system update is released. Developers of third-party privacy browsers are working on independent mitigations, but a comprehensive fix ultimately requires Apple to update the core WebKit framework. Until then, the conflict between convenient passwordless authentication and robust IP masking remains a critical challenge for mobile security.
Originally reported by Engadget
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0