By Interestana AI Editorial — AI-drafted, human-overseen. How we report
iCloud Private Relay Flaw Exposes User IPs Via WebKit

Cybersecurity researchers have identified a significant security flaw within Apple's iCloud Private Relay feature, which can inadvertently expose a user's real IP address. This vulnerability stems from specific bypasses within the WebKit framework that undermine the privacy protections offered by the service. iCloud Private Relay, a feature designed to enhance user privacy, was introduced by Apple with the release of iOS 15. It operates on a dual-hop proxy architecture, routing Safari web traffic through two distinct relays. This design aims to prevent any single entity, including Apple itself, from correlating a user's online activity with their actual IP address, thereby masking their identity and location.
The researchers, who disclosed their findings, demonstrated that by exploiting certain WebKit proxy bypasses, it is possible to circumvent the intended privacy safeguards of Private Relay. This means that despite the feature being active, a user's true IP address can be revealed to websites or third parties. The implications of this vulnerability are substantial, as users who rely on iCloud Private Relay for enhanced anonymity may be unknowingly exposed. The bypasses exploit how WebKit handles certain network requests, allowing traffic to sidestep the intended relay servers and directly reveal the originating IP address. This undermines the core promise of Private Relay, which is to obscure user IP addresses from both the websites they visit and the network infrastructure itself.
While Apple's iCloud Private Relay is designed to protect user privacy by masking IP addresses, the identified WebKit bypasses create a loophole. The dual-hop system typically involves a user's IP being known only to the first relay, and the second relay only knowing the IP of the first relay, not the original user. However, the exploit allows for traffic to be routed in such a way that the final destination server can infer or directly obtain the user's original IP address. This is particularly concerning for users who utilize Private Relay for sensitive browsing activities or to circumvent geo-restrictions, as their privacy is compromised without their knowledge. The researchers have detailed the technical mechanisms behind these bypasses, highlighting specific scenarios where the vulnerability can be triggered. The effectiveness of the exploit depends on the specific configurations of the websites being visited and the way they handle network requests, but the potential for widespread exposure exists.
The disclosure of this vulnerability raises questions about the robustness of Apple's privacy features and the ongoing cat-and-mouse game between security researchers and platform providers. While Apple has not yet released a public statement or a patch for this specific issue, it is expected that the company will address the flaw to restore the integrity of iCloud Private Relay. Users who are particularly concerned about their IP address exposure may consider temporarily disabling Private Relay until a fix is implemented, although this would negate the privacy benefits the feature provides. The ongoing development and refinement of privacy-enhancing technologies are crucial in the current digital landscape, where data privacy is a paramount concern for many internet users. This incident underscores the need for continuous vigilance and rigorous security testing of such features.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.