Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses

Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses

Posted on August 6, 2026 By CWS

Recent findings have highlighted potential privacy concerns for Apple users who depend on iCloud Private Relay to maintain anonymity online. Vulnerabilities in WebKit, the engine powering iOS browsers, may inadvertently reveal users’ real IP addresses.

Understanding the WebKit Vulnerabilities

The exposure stems from a flaw in WebKit, which can reveal a visitor’s actual IP address when a website either supports or purports to support passkeys. This issue emerges when a separate network request bypasses the protected browser route during sign-in, allowing malicious sites to capture IP details.

Researchers Tommy Mysk and Talal Haj Bakry discovered this vulnerability, and 404media confirmed its existence by demonstrating how a test page could return a user’s real IP address, compromising the intended privacy protection.

Implications for User Privacy

iCloud Private Relay aims to conceal an iCloud+ subscriber’s IP address while browsing in Safari, though it does not offer the comprehensive protection of a full-device VPN. The flaw is significant as an IP address can disclose a user’s network provider and approximate location, potentially contributing to user profiling.

This vulnerability doesn’t indicate device infections or account compromises, but it does highlight a privacy breach. The technique allows malicious operators to log IP addresses without any need for the user to install software or divulge passwords, merely by interacting with passkeys on a site.

Impact on Browsing Anonymity

The WebKit flaw also affects the OnionBrowser, an iOS app using the Tor network. As iOS browsers are required to use WebKit, apps may inherit privacy limitations. OnionBrowser developer Mike Tigas noted that some leaks are controllable by Apple, while others do not affect the app under default settings.

Although the official Tor Browser remains unaffected, users seeking anonymity should recognize that Private Relay is not a substitute for comprehensive privacy tools. Users are advised to apply Apple updates and use the Tor Browser for enhanced anonymity when necessary.

Until Apple addresses the issue, caution is advised when dealing with unfamiliar websites requesting or simulating passkey support, especially where privacy is paramount. Organizations should recognize Private Relay’s limitations and adjust their security protocols accordingly.

Cyber Security News Tags:Apple, browser vulnerabilities, iCloud, IOS, IP address, Passkeys, Privacy, Private Relay, Security, WebKit

Post navigation

Previous Post: Zbtlink Routers Expose Security Flaw with Built-in Backdoor
Next Post: SQL Injection Exploits Oracle Database for SYSTEM Access

Related Posts

Post-Quantum Cryptography What CISOs Need to Know Post-Quantum Cryptography What CISOs Need to Know Cyber Security News
Ubuntu Snap-confine Vulnerability Risks Root Access Ubuntu Snap-confine Vulnerability Risks Root Access Cyber Security News
Antv NPM Packages Compromised in Supply Chain Attack Antv NPM Packages Compromised in Supply Chain Attack Cyber Security News
Vietnam Cybercrime Network Fuels Global Account Fraud Vietnam Cybercrime Network Fuels Global Account Fraud Cyber Security News
Bitter APT Hackers Exploit WinRAR Zero-Day Via Weaponized Word Documents to Steal Sensitive Data Bitter APT Hackers Exploit WinRAR Zero-Day Via Weaponized Word Documents to Steal Sensitive Data Cyber Security News
Key Administrator of World’s Most Popular Dark Web Cybercrime Platform Arrested Key Administrator of World’s Most Popular Dark Web Cybercrime Platform Arrested Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access
  • Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
  • Zbtlink Routers Expose Security Flaw with Built-in Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access
  • Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
  • Zbtlink Routers Expose Security Flaw with Built-in Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark