💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Apple’s iCloud Private Relay feature, designed to mask user identity and location while browsing Safari, contains three significant security vulnerabilities that researchers have successfully exploited. Security experts Talal Haj Bakry and Tommy Mysk identified methods by which legitimate browser technologies can circumvent the privacy protections that iCloud+ subscribers depend on, potentially revealing real IP addresses and DNS server information.
The researchers determined that DNS prefetching, WebAuthn functionality tied to passkeys, and WebTransport protocols can all bypass WebKit’s proxy configuration. Two of these mechanisms directly expose a user’s internet protocol address, while the third reveals details about DNS servers connected to the device. Notably, websites do not require users to download files or install applications to trigger these network requests—the leaks occur through standard browser operations.
DNS prefetching, a speed-optimization feature that preloads website addresses before users click links, can send lookup requests through a device’s standard DNS connection rather than through Private Relay’s protected pathway. According to the researchers, this vulnerability has existed since iOS 26.0, allowing websites to detect DNS queries originating from users’ actual networks instead of through Apple’s proxy system.
WebAuthn, the authentication standard powering passkeys, includes a verification mechanism for websites operating under related domains. This verification process can contact servers directly, bypassing Safari’s proxy configuration and revealing the device’s genuine IP address to destination servers. The researchers emphasized this flaw does not enable passkey theft but rather exposes network information during the verification request.
WebTransport, a protocol that enables faster low-latency connections for interactive web services, can establish direct connections from devices instead of routing through configured proxies. When this occurs, receiving servers can identify users’ actual IP addresses. This functionality became available on iOS with version 26.4.
The implications extend beyond Safari to any privacy-focused browsers or applications utilizing WebKit’s proxy configuration across iOS and macOS platforms. Virtual private networks do not suffer from these specific vulnerabilities because they tunnel network traffic at the system level rather than relying on browser-level proxy settings. However, VPNs offer no protection against tracking methods involving account logins, cookies, and other identification signals.
While IP addresses typically do not directly reveal home addresses, they can expose internet service providers, approximate geographic location, and provide websites with additional identifiers to correlate with previously collected data. For users relying on Private Relay specifically to prevent this information exposure, these gaps represent meaningful privacy breaches.
Users currently relying on Private Relay should install the latest iOS, iPadOS, and macOS updates when released, as Apple typically addresses security issues through operating system patches. Apple has listed iOS 26.6 as its most recent iPhone software release. Additionally, users concerned about IP address exposure can disable Private Relay through Settings or consider implementing a reputable VPN service offering system-level protection. The browser developer Psylo has already implemented fixes, with version 1.3.1 blocking DNS prefetch hints and disabling WebTransport and WebAuthn by default.
Apple did not respond to requests for comment regarding the researchers’ findings before publication. Security experts note that these vulnerabilities highlight the importance of understanding the specific protections offered by privacy features and recognizing their limitations when complete anonymity is essential.
More Stories
Waist Size May Predict Heart Disease Risk Better Than BMI, Research Shows
LIV Golf Star Poulter Warns Tour Could Collapse by September Deadline
Puerto Rico Grapples With Severe Water Emergency as Drought and Aging Systems Strain Island