WebKit Vulnerability Exposes iOS Users’ IP Addresses Despite Private Relay
At a glance
- Researchers found WebKit features leaking real IP addresses on iOS
- All iOS browsers using WebKit, including Safari, are affected
- Apple is investigating and plans a fix in Fall 2026
Security researchers identified a vulnerability in WebKit that allows some iOS browsers to bypass iCloud Private Relay, exposing users’ actual IP addresses. This development is relevant because iCloud Private Relay is intended to keep users’ web activity and IP addresses private.
Talal Haj Bakry and Tommy Mysk discovered that three specific WebKit features can send traffic directly from the device, bypassing iCloud Private Relay. This process reveals the user’s real IP address, which Private Relay is designed to protect.
The vulnerability impacts all browsers on iOS that depend on WebKit, including both Safari and OnionBrowser. WebKit is the browser engine required by Apple for all iOS web browsers, making the issue widespread across the platform.
iCloud Private Relay is structured to route Safari web traffic and DNS queries through two separate relays. According to Apple’s legal documentation, this system is intended to prevent any single party from accessing both the user’s IP address and the websites they visit.
What the numbers show
- Three WebKit features were identified as bypassing Private Relay
- All iOS browsers using WebKit are affected, including Safari and OnionBrowser
- Apple plans to address the issue in Fall 2026
The researchers who discovered the vulnerability reported their findings to Apple. Apple responded by stating it is investigating the issue and intends to implement a fix in Fall 2026.
The investigation and planned response from Apple indicate that the company is aware of the issue and is working toward a resolution. The timeline for the fix has been set for later in 2026, according to Apple’s response to the researchers.
Until the fix is released, all iOS browsers that rely on WebKit remain affected by this vulnerability. Users of these browsers may have their real IP addresses exposed when using certain features, despite having iCloud Private Relay enabled.
This incident highlights the importance of ongoing security research and prompt vendor response in addressing privacy vulnerabilities in widely used software platforms.
* This article is based on publicly available information at the time of writing.
Sources and further reading
Note: This section is not provided in the feeds.
More on Technology
-
Lynk Global and Omnispace Complete Merger to Form Elveo Mobile
A merger was finalized on August 14, 2026, resulting in the formation of Elveo Mobile, according to company statements.
-
AI Tokenomics Drives Unpredictable Costs for Enterprise Buyers
Enterprises report an 18.6-fold increase in AI token usage per developer. Hybrid pricing models are now common, according to industry reports.
-
Waymo Expands Driverless Robotaxi Service to More US Cities
Waymo's driverless robotaxi service now covers over 1,400 square miles in 11 US cities, with plans for further expansion, according to reports.
-
Crane Safety Systems Advance With AI and Real-Time Monitoring
Recent advancements in crane safety include AI and real-time monitoring to improve operations and reduce hazards, according to reports.
-
How to Disable Gemini AI Features in Google Workspace
Users can disable Gemini AI features in Google Docs and Gmail through menu settings, providing control over smart prompts and assistance bars.