Back

WebKit Vulnerability Exposes iOS Users’ IP Addresses Despite Private Relay

At a glance

  • Researchers found WebKit features leaking real IP addresses on iOS
  • All iOS browsers using WebKit, including Safari, are affected
  • Apple is investigating and plans a fix in Fall 2026

Security researchers identified a vulnerability in WebKit that allows some iOS browsers to bypass iCloud Private Relay, exposing users’ actual IP addresses. This development is relevant because iCloud Private Relay is intended to keep users’ web activity and IP addresses private.

Talal Haj Bakry and Tommy Mysk discovered that three specific WebKit features can send traffic directly from the device, bypassing iCloud Private Relay. This process reveals the user’s real IP address, which Private Relay is designed to protect.

The vulnerability impacts all browsers on iOS that depend on WebKit, including both Safari and OnionBrowser. WebKit is the browser engine required by Apple for all iOS web browsers, making the issue widespread across the platform.

iCloud Private Relay is structured to route Safari web traffic and DNS queries through two separate relays. According to Apple’s legal documentation, this system is intended to prevent any single party from accessing both the user’s IP address and the websites they visit.

What the numbers show

  • Three WebKit features were identified as bypassing Private Relay
  • All iOS browsers using WebKit are affected, including Safari and OnionBrowser
  • Apple plans to address the issue in Fall 2026

The researchers who discovered the vulnerability reported their findings to Apple. Apple responded by stating it is investigating the issue and intends to implement a fix in Fall 2026.

The investigation and planned response from Apple indicate that the company is aware of the issue and is working toward a resolution. The timeline for the fix has been set for later in 2026, according to Apple’s response to the researchers.

Until the fix is released, all iOS browsers that rely on WebKit remain affected by this vulnerability. Users of these browsers may have their real IP addresses exposed when using certain features, despite having iCloud Private Relay enabled.

This incident highlights the importance of ongoing security research and prompt vendor response in addressing privacy vulnerabilities in widely used software platforms.

* This article is based on publicly available information at the time of writing.

Sources and further reading

Note: This section is not provided in the feeds.

Related Articles

  1. A security update was released on February 12, 2026, addressing CVE-2026-20700, according to reports. CISA included the flaw in its catalog.

  2. Artemis II is scheduled for launch no earlier than April 2026. Artemis V aims to initiate Moon base construction in late 2028, according to reports.

  3. A newly identified spyware, ZeroDayRAT, targets iOS and Android devices, exploiting phishing methods for data access, according to security reports.

  4. Analysts project that oil prices above $100 per barrel could slow U.S. GDP growth and raise inflation, according to recent financial assessments.

  5. A proposal outlines the creation of a UK Deportation Command to detain 24,000 and deport 288,000 annually, according to reports.

More on Technology

  1. A merger was finalized on August 14, 2026, resulting in the formation of Elveo Mobile, according to company statements.

  2. Enterprises report an 18.6-fold increase in AI token usage per developer. Hybrid pricing models are now common, according to industry reports.

  3. Waymo's driverless robotaxi service now covers over 1,400 square miles in 11 US cities, with plans for further expansion, according to reports.

  4. Recent advancements in crane safety include AI and real-time monitoring to improve operations and reduce hazards, according to reports.

  5. Users can disable Gemini AI features in Google Docs and Gmail through menu settings, providing control over smart prompts and assistance bars.