Cybersecurity researchers have identified a significant vulnerability in Apple’s iCloud Private Relay, potentially revealing users’ true IP addresses. This flaw, discovered by experts Talal Haj Bakry and Tommy Mysk, compromises the privacy of the service, which is designed to protect users’ online activity.
Launched with iOS 15 and included with iCloud+ subscriptions, iCloud Private Relay routes Safari web traffic through two relays, ensuring no single entity, not even Apple, can trace the origin or destination of the request. However, the researchers pinpointed issues within Apple’s WebKit, specifically tied to DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. These components bypass the configured proxy, directly exposing the user’s network.
WebKit Features’ Risks
The WebKit issues extend to macOS and other WebKit-based browsers, revealing the device’s actual IP address. DNS prefetching resolves hostnames through the device’s standard DNS pathway, ignoring the browser’s proxy settings. WebAuthn Related Origin Requests and WebTransport further exacerbate the problem by making direct connections that sidestep proxy configurations.
WebAuthn is particularly concerning as it allows websites supporting the standard to access users’ real IP addresses, regardless of iCloud Private Relay’s activation. This occurs without user interaction, merely requiring a website to exploit the vulnerability deliberately.
Implications and Testing
To demonstrate the vulnerability, a proof-of-concept website, “leaks.psylo[.]app,” enables users to check if their IP addresses leak despite having Private Relay enabled. While desktop versions of browsers like Chrome are unaffected, the issue remains a concern for Safari and other WebKit-based browsers.
Mysk clarified that the risk is mitigated when users connect through a VPN, providing an additional layer of privacy. However, this revelation emphasizes the need for users to remain vigilant about their online privacy.
Apple’s Response and Ongoing Concerns
Apple has yet to publicly respond to the vulnerability, but the company has informed 404 Media of its ongoing investigation into the researchers’ findings. This incident is not isolated, as previous issues have been uncovered in iCloud Private Relay since its 2021 debut, including a WebRTC-related leak identified by FingerprintJS.
In light of these findings, users and cybersecurity professionals continue to scrutinize Apple’s privacy features, underscoring the importance of transparency and timely resolutions to maintain trust in digital privacy tools.
