Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apple iCloud Private Relay Vulnerability Exposes IPs

Apple iCloud Private Relay Vulnerability Exposes IPs

Posted on August 6, 2026 By CWS

Cybersecurity researchers have identified a significant vulnerability in Apple’s iCloud Private Relay, potentially revealing users’ true IP addresses. This flaw, discovered by experts Talal Haj Bakry and Tommy Mysk, compromises the privacy of the service, which is designed to protect users’ online activity.

Launched with iOS 15 and included with iCloud+ subscriptions, iCloud Private Relay routes Safari web traffic through two relays, ensuring no single entity, not even Apple, can trace the origin or destination of the request. However, the researchers pinpointed issues within Apple’s WebKit, specifically tied to DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. These components bypass the configured proxy, directly exposing the user’s network.

WebKit Features’ Risks

The WebKit issues extend to macOS and other WebKit-based browsers, revealing the device’s actual IP address. DNS prefetching resolves hostnames through the device’s standard DNS pathway, ignoring the browser’s proxy settings. WebAuthn Related Origin Requests and WebTransport further exacerbate the problem by making direct connections that sidestep proxy configurations.

WebAuthn is particularly concerning as it allows websites supporting the standard to access users’ real IP addresses, regardless of iCloud Private Relay’s activation. This occurs without user interaction, merely requiring a website to exploit the vulnerability deliberately.

Implications and Testing

To demonstrate the vulnerability, a proof-of-concept website, “leaks.psylo[.]app,” enables users to check if their IP addresses leak despite having Private Relay enabled. While desktop versions of browsers like Chrome are unaffected, the issue remains a concern for Safari and other WebKit-based browsers.

Mysk clarified that the risk is mitigated when users connect through a VPN, providing an additional layer of privacy. However, this revelation emphasizes the need for users to remain vigilant about their online privacy.

Apple’s Response and Ongoing Concerns

Apple has yet to publicly respond to the vulnerability, but the company has informed 404 Media of its ongoing investigation into the researchers’ findings. This incident is not isolated, as previous issues have been uncovered in iCloud Private Relay since its 2021 debut, including a WebRTC-related leak identified by FingerprintJS.

In light of these findings, users and cybersecurity professionals continue to scrutinize Apple’s privacy features, underscoring the importance of transparency and timely resolutions to maintain trust in digital privacy tools.

The Hacker News Tags:Apple, Cybersecurity, DNS, iCloud, Private Relay, Security, Vulnerability, WebAuthn, WebKit, WebTransport

Post navigation

Previous Post: Critical Jenkins Flaw Enables Malicious Code Execution
Next Post: Remus Malware Exploits Ethereum for Stealthy Data Theft

Related Posts

Trojanized Gaming Tools Spread Java RAT via Online Platforms Trojanized Gaming Tools Spread Java RAT via Online Platforms The Hacker News
Critical U-Boot Vulnerabilities Discovered in Firmware Security Critical U-Boot Vulnerabilities Discovered in Firmware Security The Hacker News
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access The Hacker News
Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks The Hacker News
Lazarus Group Targets Finance with RemotePE Malware Lazarus Group Targets Finance with RemotePE Malware The Hacker News
INTERPOL Arrests 1,209 Cybercriminals Across 18 African Nations in Global Crackdown INTERPOL Arrests 1,209 Cybercriminals Across 18 African Nations in Global Crackdown The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Remus Malware Exploits Ethereum for Stealthy Data Theft
  • Apple iCloud Private Relay Vulnerability Exposes IPs
  • Critical Jenkins Flaw Enables Malicious Code Execution
  • AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas
  • Over 4,400 Rockwell Controllers Vulnerable Online

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Remus Malware Exploits Ethereum for Stealthy Data Theft
  • Apple iCloud Private Relay Vulnerability Exposes IPs
  • Critical Jenkins Flaw Enables Malicious Code Execution
  • AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas
  • Over 4,400 Rockwell Controllers Vulnerable Online

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark