Apple's iCloud Private Relay Leaks Users' Real IP Addresses, Affecting All iOS Browsers
404 Media · rss · 2026-08-05
Security researchers Tommy Mysk and Talal Haj Bakry discovered multiple vulnerabilities in Apple's iCloud Private Relay (paid iCloud+ feature) that can expose users' real IP addresses. The issue stems from passkey (WebAuthn) implementation in WebKit, where requests from the OS credential service bypass the Private Relay proxy. The issue also affects OnionBrowser, an iOS Tor browser. Apple is investigating. Previously, Apple's Hide My Email was also found to leak real email addresses.
More from Safety
- External Guardrails Are Crucial for Current Deployments, Need Adversarial Control — dhadfieldmenell · 2026-08-05
- ChatGPT Allegedly Leaks Boss's Name, Sparking Corporate Privacy Concerns — hellojello07 · 2026-08-05
- Economists in AI Safety: A Pipeline from BlueDot to MATS — aniketapanjwani · 2026-08-05
- Apollo Research Opens Applications for SPAR AI Safety Project — austinc3301 · 2026-08-05
- Felony Bench: A Sarcastic Benchmark Rating LLMs on Cybercrime Capabilities — RebeccaBellan · 2026-08-05
- Refuting Open-Source AI Virus Threats: Consumer Hardware Can't Handle It — basedjensen · 2026-08-05