If you’re an iCloud+ subscriber using Safari, you might have turned on iCloud Private Relay for extra privacy. This feature is designed to keep websites from tracking your real IP address and exact location. However, a recent discovery by security researchers has unveiled a few ways that certain elements of WebKit can slip past its protections.
Talal Haj Bakry and Tommy Mysk found that features like DNS prefetching, passkeys, and the WebAuthn function related to WebTransport can bypass the proxy settings of WebKit. Notably, two of these methods can expose your actual IP address, while another might disclose details about the DNS servers your device utilizes. The unsettling part is that these are all legitimate browser functions. This means a website doesn’t necessarily need to convince users to download anything dubious to generate network requests.
So, let’s dive into how these breaches work, who might be affected, and what you can do to safeguard your privacy.
How iCloud Private Relay Offers Protection
For those unfamiliar, Apple’s iCloud Private Relay is available to iCloud+ users and operates with Safari. When activated, Apple sends your requests through two separate Internet relays. While your ISP can see your IP address, your DNS records remain encrypted. The second relay provides the website with a temporary IP address rather than your actual one.
This method aims to ensure that no single entity can track your identity or browsing habits effectively. It’s particularly handy for minimizing the location and browsing details that websites gather about you. Yet, the recently reported behavior within WebKit creates opportunities for leakage.
How WebKit Can Leak Information
Researchers pinpointed three mechanisms that operate somewhat differently.
DNS Prefetching Can Reveal Network Paths
Often, browsers try to enhance loading times by looking up a website’s address prior to a click. This process, known as DNS prefetching, is usually expected to follow the same privacy protocols as the rest of your browsing. However, it turns out that WebKit can send DNS requests through the normal DNS connection of your device. This results in websites receiving requests that may originate from your real network instead of through the proxy. Reports indicate this issue has been affecting iOS since version 26.0.
While this doesn’t completely undermine your online activity, the network information that the Private Relay aimed to protect could be exposed.
Requests Linked to Passkeys Can Expose Your IP
The second vulnerability is related to WebAuthn, the standard used for passkeys. Companies with multiple websites often need one passkey to function across those domains. To verify if websites are validated as the same, the operating system might directly access the relevant website for a tiny verification file.
According to researchers, this request can occur outside of Safari’s normal proxy network, which means the actual IP address could be sent to the server itself, even with Private Relay active. It’s crucial to note that this leakage does not mean attackers can steal the passkeys; the privacy issue arises from network requests used during validation.
WebTransport Can Establish Direct Connections
WebTransport allows websites to create a fast, low-latency connection with servers, which is beneficial for interactive services. Yet, researchers revealed that WebKit can set up WebTransport connections directly from the device instead of routing them through the configured proxy. Consequently, the server involved will be able to see your real IP address. Private relays won’t intercept these connections because they occur outside of the protective network path.
Which Apple Users Might Be Impacted?
This issue is particularly relevant for those who depend on Safari and iCloud Private Relay to mask their IP address. It could also affect privacy-focused browsers and applications utilizing WebKit proxy configurations, especially those at play on iOS and macOS.
Importantly, researchers have noted that VPNs do not face the same WebKit proxy leaks as they tunnel data at the system level rather than relying on WebKit’s browser-level settings. Of course, this doesn’t imply that a VPN is a catch-all solution for online tracking. Websites can still figure out who you are through cookies, login info, and other online identifiers.
What the iCloud Private Relay Leak Means for You
If you’re using Private Relay, there’s no immediate cause for alarm, nor should you deactivate it right away. Most of your Safari browsing should still adhere to the usual privacy protocols. Apple asserts that this service aims to keep websites from accessing your IP address or specific location when you browse. The catch is that some WebKit features can cause exceptions.
For websites utilizing these features, there’s a chance they could glean information about your true IP and DNS connections. Usually, you wouldn’t receive a heads-up on this. Your IP address doesn’t typically reveal your exact home address, but your ISP and general location might be exposed. Plus, you could inadvertently provide websites with other identifiers that let them link this info with other data they gather about you. This is especially significant for users of private relays, as they often desire to limit such exposure.
Apple has been contacted regarding these findings, but there was no response by the time of this report.
How to Protect Your Privacy While Using Safari
If you’re worried about this WebKit behavior, there are steps you can take to enhance your privacy.
Keep Private Relay Activated
Disabling Private Relay would remove the protection that currently covers your Safari traffic. You can verify its status by going to [Settings] > [Your Name] > [iCloud] > [Private Relay] on your iPhone.
Apple also allows you to choose whether to share your general location or just your country and time zone.
Ensure Your Apple Devices Are Updated
Always install new updates for iOS, iPadOS, or macOS when Apple releases them. For iPhone, navigate to [Settings] > [General] > [Software Update]. Keeping your device updated is vital since many security and privacy updates are incorporated within these operating system updates.
If IP Privacy is Critical, Consider a VPN
If hiding your real IP address is pivotal for you, using a trustworthy VPN could add another layer of protection. Researchers pointed out that VPNs are shielded against these specific WebKit leak issues because they function at the system level. Just remember that utilizing a VPN doesn’t make you completely invisible; a website can still identify you using account logins or other identifying details.
Continue Using Passkeys
Although the findings surrounding WebAuthn may seem concerning due to their connection to passkeys, it’s important to note that there’s no indication that attackers can hijack these passkeys through this flaw. Passkeys still represent some of the strongest defenses available against phishing and password hacking.
Stay Informed About Browser Privacy Updates
Developers, for instance, have already adjusted how browsers handle these mechanisms, indicating progress. Staying updated can help close specific security gaps.
In Summary
Understanding what privacy features are actually protecting you plays a key role in how effectively they work. I find value in iCloud Private Relay as it offers meaningful protection for Safari users without much effort. However, I think it wouldn’t hurt to treat it as a complement to a full device VPN if your primary concern is keeping your real IP address hidden. What really troubles me is how subtle these exceptions are; you might activate a privacy feature, ensure it’s running, and reasonably expect it to cover all necessary connections. These findings show the underlying mechanisms are just as crucial as the privacy switches visible in your settings. With Apple promoting privacy heavily in its marketing, it’s all the more essential for users to comprehend where these protections fall short.
Has the discovery that websites can bypass private relays affected your trust in this feature? Or are you going to stick with it until Apple manages to patch the loophole? Feel free to share your thoughts.






