Apple Investigating Privacy Flaw in iCloud Private Relay 

Apple iCloud Private Relay Privacy Flaw Under Investigation | CyberPro Magazine

Key Takeaways: 

  • Security researchers discover severe WebKit flaws exposing user IP addresses via passkeys.
  • Apple iCloud Private Relay fails to mask network data during automated credential service requests.
  • Apple acknowledges the reported privacy vulnerabilities while investigating potential fixes for users.

Apple Privacy Tool Leaks Data

Independent security researchers revealed this week that Apple iCloud Private Relay fails to protect user anonymity, allowing malicious websites to expose real IP addresses.

The security vulnerability stems from how the WebKit browser engine handles passkey requests through the WebAuthn standard. Because the operating system’s credential service issues web requests directly from the device, traffic bypasses the proxy path entirely.

“Any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having Apple iCloud Private Relay enabled,” stated security researcher Tommy Mysk. Analysts note that this flaw undermines core privacy expectations for paid cloud subscribers.

Uncovering WebKit Engine Flaws

The investigation uncovered multiple underlying architectural weaknesses within Apple’s software framework that compromise proxy routing. In addition to passkey protocol errors, researchers identified leaks originating from DNS prefetching and WebTransport functions.

Because iOS mandates that all mobile web browsers utilize the WebKit engine, the security gaps also affect third-party applications relying on proxy and anonymity configurations. Technical experts emphasize that these structural flaws require deep operating system modifications to resolve permanently.

“These issues are entirely based on how iOS and WebKit work and solely in Apple’s hands,” noted app developer Mike Tigas. Industry specialists recommend using traditional virtual private networks for comprehensive device-level protection until official software patches arrive.

Evaluating Industry Security Impacts

The discovery represents the second major privacy product blemish for Apple iCloud Private Relay following a recent email-masking vulnerability. Cybersecurity advocates continue pressing major technology corporations to audit background data-handling processes rigorously.

Apple representatives confirmed receipt of the security report and stated that engineering teams are actively investigating the findings related to Apple iCloud Private Relay. Affected consumers await a definitive timeline for software updates addressing the proxy bypasses.

“We have already informed them, and they said the issue was dire,” Mysk added regarding ongoing communications with corporate officials. Stakeholders expect further technical advisories as vulnerability testing expands across global markets.

Visit CyberPro Magazine For The Most Recent Information.

LinkedIn
Twitter
Facebook
Reddit
Pinterest