Apple's iCloud Private Relay, a privacy feature designed to conceal users' IP addresses while browsing in Safari, comes under scrutiny. This comes after security researchers disclosed WebKit flaws could expose users' real IP addresses. The findings suggest that websites can bypass Private Relay under certain conditions. Apple has acknowledged the report and is investigating the issue.
Private Relay is available to iCloud+ subscribers and routes Safari traffic through two separate internet relays. The architecture prevents websites from directly identifying a user's IP address and location. However, researchers say some WebKit components do not always follow this protected path.
Privacy researchers Tommy Mysk and Talal Haj Bakry identified three WebKit features that can bypass Apple's proxy mechanism. These include:
WebAuthn requests used during passkey authentication
DNS prefetching
WebTransport connections
According to the researchers, “ These requests may be sent directly from the device instead of passing through Private Relay. As a result, websites can receive the user's real IP address even when the privacy feature is enabled. Since Apple requires all browsers on iOS to use WebKit, the issue affects Safari as well as other WebKit-based browsers on iPhone and iPad.”
According to the researchers, the biggest problem is the use of passkeys. A website that supports, or even claims to support, passkey authentication can trigger a WebAuthn request that bypasses Private Relay.
The researchers also published a proof-of-concept demonstration showing how a website can retrieve a visitor's real IP address. Apple is yet to bring a fix and confirmed that it is reviewing the findings. Until patches become available, users should use a trusted VPN rather than relying solely on iCloud Private Relay for IP protection.
Also Read: Apple Pay Goes Live in the Philippines