CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

WebKit Proxy Bypasses Can Expose Real IP Addresses Despite iCloud Private Relay

August 6, 2026

Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay that can expose a user’s real IP address. The problem is rooted in three features in Apple’s WebKit: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. These features bypass the configured proxy and send traffic directly from the device, exposing the user’s real network. The issues affect Safari and all WebKit-based browsers on iOS, iPadOS, and macOS.

Researchers Talal Haj Bakry and Tommy Mysk found that any website can configure WebAuthn in a way that causes WebKit to reveal the browser’s real IP address, bypassing both proxy configurations and iCloud Private Relay. This does not require user interaction or the use of passkeys. A proof-of-concept website named leaks.psylo[.]app has been made available for users to check if their real IP address leaks.

Apple has not immediately responded to a request for comment but told 404 Media that it is investigating the researchers’ report. This is not the first time security issues have been discovered in iCloud Private Relay; in 2021, FingerprintJS highlighted a WebRTC-based mechanism that leaked a client’s real IP address. The disclosure comes over a month after Apple addressed another vulnerability in its Hide My Email service.

CVEs: CVE-2026-50522

Companies: Apple, FingerprintJS, 404 Media

Products: iCloud Private Relay, WebKit, Safari, Hide My Email