Security researchers Talal Haj Bakry and Tommy Mysk discovered three WebKit flaws that bypass Apple's iCloud Private Relay, exposing users' real IP addresses. The most critical involves passkeys: any website supporting passkeys can trigger the OS credential service to fetch a validation file directly, bypassing Private Relay entirely — no login required. Two other leaks involve DNS prefetching and WebTransport, both routing traffic outside the proxy. Because Apple mandates WebKit for all iOS browsers, the flaws also affect privacy-focused browsers like OnionBrowser on iOS. Apple acknowledged the issues and plans a fix for autumn 2026. The researchers have a conflict of interest — they ship a rival iOS browser, Psylo, that already patches all three leaks — but the bugs have been independently verified as real and reproducible.

4m read timeFrom thenextweb.com
Post cover image
Table of contents
Three ways out of the tunnelIt breaks iOS Tor tooApple’s privacy problem
7 Impressions