Apple iCloud Private Relay IP leak
Analysis based on 30 articles · First reported Aug 05, 2026 · Last updated Aug 11, 2026
The disclosure may raise privacy concerns among iCloud+ subscribers, potentially affecting Apple's reputation for privacy and its services revenue. However, the impact is likely limited as the flaw is technical and does not affect core device functionality, and Apple is expected to address it in a future update.
Security researchers Tommy Mysk and Talal Haj Bakry disclosed that Apple's ICloud, a privacy feature for Safari, can leak users' real IP addresses. The flaw stems from WebKit features, particularly WebAuthn (passkeys), which bypass Safari's proxy and make direct network requests from the operating system, exposing the user's IP to websites that support or pretend to support passkeys. Additionally, Link prefetching (IOS 26) and WebTransport (IOS 26.4) can also reveal IP or DNS information. The issue affects all IOS browsers due to Apple's WebKit mandate, and also Onion Browser. Apple has acknowledged the report and is investigating, but no fix has been released. This is the second recent Apple privacy stumble, following the ICloud vulnerability. Users are advised to use a full-device VPN for complete protection.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard