Researchers have uncovered three ways WebKit features can undermine the privacy protections offered by Apple's iCloud Private Relay. Depending on the feature involved, the issues can expose a user's IP address or bypass parts of Private Relay's protected network path. Security researchers Talal Haj Bakry and Tommy Mysk detailed the bypasses, which affect both Safari and other browsers that rely on WebKit's proxy infrastructure.
Private Relay protects Safari web browsing by routing traffic through two separate relays so that neither Apple nor the websites a user visits can see both their identity and destination. Unlike a system-wide VPN, it does not tunnel all traffic from every app. The newly uncovered leaks occur because certain browser features perform network requests outside the normal page-loading path, meaning they never pass through Private Relay's proxies. The researchers emphasized that traditional VPNs are not affected because they tunnel the device's entire network traffic at the operating system level.
One issue involves WebAuthn related-origin requests. A website can initiate one—even silently, without displaying a passkey prompt—which causes the operating system's credential service to fetch a validation file directly from the device. Because that request is issued outside Private Relay's proxied path, the website receives the visitor's actual IP address with no visible indication.
Two additional issues were also identified. DNS prefetching, added to WebKit in iOS 26, resolves hostnames outside the proxy path, allowing a site's authoritative DNS server to observe lookups originating from the user's real network rather than through Private Relay. WebTransport, introduced in iOS 26.4, opens a direct HTTP/3 connection that bypasses the proxy, revealing the connection's originating IP address.
The impact extends beyond Safari. Because every browser on iOS must use WebKit, the issues also affect third-party browsers that rely on Apple's proxy configuration API, including some Tor-based browsers. According to 404 Media, the researchers said Apple described the issue as "dire" but did not provide a timeline for a fix. Apple separately told the publication that it is investigating the report.
The researchers have created a proof-of-concept site at leaks.psylo.app where users can check whether their IP address is leaking. They also released Psylo 1.3.1, which blocks DNS prefetching and disables WebTransport and WebAuthn by default while providing per-site toggles for websites that genuinely need those features.
Get the iClarified Daily Newsletter
Apple news, rumors, tutorials, price drop alerts, in your inbox every evening, free.
Unsubscribe at any time.
Success!
You have been subscribed.
Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?