News

    Critical iCloud IP Leak Vulnerability Discovered by Researchers

    Security researchers have discovered an iCloud IP leak vulnerability affecting iCloud Private Relay. Learn how passkey technology and WebKit flaws expose your data.

    Security researchers Tommy Mysk and Talal Haj Bakry have uncovered a significant vulnerability in Apple’s iCloud Private Relay, revealing that the service fails to effectively mask user IP addresses under specific technical conditions. Designed to enhance online privacy for iCloud+ subscribers by obfuscating IP and DNS information during Safari browsing, the service is currently experiencing leaks that expose users to potential tracking. The flaw primarily affects interactions involving WebAuthn and passkey technology, where the system bypasses the intended proxy route. As Apple reviews these findings, the discovery highlights ongoing challenges in maintaining robust anonymity across the WebKit framework used by iOS and third-party browsers.

    • Researchers identified that passkey authentication requests bypass the iCloud Private Relay proxy infrastructure.
    • The WebKit framework contains additional vulnerabilities that expose user DNS data and IP addresses through WebTransport and DNS prefetching features.
    • Apple has acknowledged the report and is currently investigating the technical scope of these security gaps.
    • Security experts recommend that users rely on reputable VPN services until a formal patch is released.

    Passkey Technology Bypass Creates Security Risks

    The core of the issue lies in how the WebKit engine handles passkey authentication. When a website utilizes the WebAuthn standard, the authentication process shifts from the browser to the device’s internal credential service. Because this service initiates HTTPS requests directly, the traffic does not pass through the encrypted tunnel provided by iCloud Private Relay. Consequently, websites can identify the user’s real IP address without requiring any explicit interaction or triggering security alerts.

    This technical oversight effectively neutralizes the primary privacy protections promised by Apple’s subscription-based security feature.

    Additional Vulnerabilities Affect WebKit Performance

    Beyond the passkey issue, Mysk and Haj Bakry identified that other features within the WebKit architecture further compromise user privacy. Specifically, the DNS prefetching functionality introduced in recent iOS versions can inadvertently broadcast a user’s actual DNS server configurations. Furthermore, the implementation of WebTransport has been shown to facilitate direct IP address leaks. Because these vulnerabilities are baked into the underlying browser engine, the risk extends beyond Safari to include various third-party applications that rely on WebKit for web content rendering.

    Users Must Seek Alternative Protection Methods

    Apple has officially confirmed that its engineering teams are reviewing the documentation provided by the researchers. While a software update is anticipated to address these flaws, the company has not provided a specific timeline for the remediation. In the interim, privacy-conscious users are advised to employ established VPN solutions to ensure their network traffic remains masked. The researchers have also provided a dedicated testing tool that allows individuals to verify whether their own devices are susceptible to these specific data leaks. As the digital landscape evolves, the reliance on proprietary privacy tools requires constant verification and independent security auditing to remain effective against sophisticated tracking methods.

    Given the critical nature of these privacy concerns, how do these findings change your perspective on using iCloud Private Relay for your daily browsing, and will you be switching to a third-party VPN service until Apple issues a fix?

    No comments yet Write the First Comment
    ×

    Your comment has been submitted,
    it will be published after approval.

    Write a Comment