WebKit flaw exposes real IP addresses of iOS and Mac users

iCloud Private Relay and Tor all rely on WebKit and cannot be trusted to keep your address to itself

Must Read

- Advertisement -
- Advertisement -
  • Implications are especially serious for journalists, activists, dissidents, and others who rely on proxy-based anonymity tools.
  • A comprehensive fix requires Apple to modify WebKit so that DNS prefetching, WebAuthn-related requests, and WebTransport all respect the user’s proxy configuration by default.
  • The practical takeaway for users is straightforward: if you require genuine IP anonymity on iOS or macOS, a device-level VPN is the only reliable option.

Modern browsers on iOS and macOS are leaking users’ real IP addresses even when proxy configurations are explicitly enabled, according to a report published on August 4, 2026 by the security research team Mysk.

The findings reveal that Apple’s iCloud Private Relay — alongside third-party proxy browsers and even the Tor browser on iOS — fails to fully shield user identities due to three distinct bypass mechanisms baked into WebKit, the mandatory rendering engine for all browsers on Apple’s platforms.

The discovery, made by developers Talal Haj Bakry and Tommy Mysk, exposes a troubling gap between the privacy guarantees Apple markets and the actual behaviour of its software. Only device-level VPNs, which tunnel an entire machine’s network traffic, remain unaffected by the leaks.

Bypassing proxy settings

The Mysk team identified three specific WebKit features that route traffic directly from the device, circumventing any proxy or relay configuration a user has set up.

DNS Prefetching is a performance optimisation that allows websites to resolve domain names before a user actually clicks a link. WebKit, however, performs these DNS lookups through the device’s default resolver rather than through the configured proxy.

The result is that a user’s real DNS server — and by extension their approximate location and ISP — is exposed to any site embedding a prefetch hint in its HTML. The researchers noted that this mechanism alone can decloak a user who believes they are browsing anonymously.

WebAuthn Related Origin Requests present a more insidious vector. WebAuthn is the industry standard underpinning passkey-based authentication, and the “Related Origin Requests” feature allows the same passkey credential to be reused across multiple domains belonging to the same organisation.

The problem lies in how these requests are dispatched: they are issued by the operating system’s credential service, not by the browser itself, and therefore ignore any proxy configuration entirely. A malicious website can exploit this by tricking the system into contacting an attacker-controlled server, revealing the user’s real IP address without any visible indication.

WebTransport, a newer communication protocol available since iOS 26.4, opens HTTP/3 connections directly from the device and similarly bypasses proxy tunnels. The Mysk report notes that Onion Browser and other Tor-based browsers on iOS are not affected by this particular vector, as they ship with WebTransport disabled by default. However, every other WebKit browser remains vulnerable.

iCloud Private Relay is not immune

Apple markets iCloud Private Relay, included with every iCloud+ subscription, as a service that ensures “no single party — including Apple — can see what users are doing or what they’re visiting.”

The system is designed to encrypt DNS records and route traffic through two separate relay servers before it ever reaches the destination website.

Yet all three WebKit leaks affect iCloud Private Relay, according to Mysk’s analysis. Traffic that should be invisibly routed through Apple’s relay infrastructure instead travels directly from the device, exposing the user’s real network identity.

The researchers set up a test website so users can verify whether their own Private Relay configuration is leaking their IP address.

The irony is stark: a paid privacy feature that Apple positions as a key differentiator for its ecosystem is undermined by the very engine Apple mandates for all browser activity on its platforms.

Scale of the problem

Because every browser on iOS — whether Chrome, Firefox, Brave, Edge, or any alternative — is required by Apple’s App Store policies to use WebKit under the hood, the leaks are universal. There is no alternative rendering engine a privacy-conscious iOS user can switch to.

The only workaround is a device-level VPN, which routes all network traffic through an encrypted tunnel at the operating system level and therefore sits below the layer where WebKit makes its errant direct connections.

The implications are especially serious for journalists, activists, dissidents, and others who rely on proxy-based anonymity tools. An exposed IP address can deanonymise a source, reveal a user’s physical location, and in some jurisdictions, put individuals at genuine physical risk.

For years, users operating under the assumption that iCloud Private Relay or a proxy-configured Tor browser was keeping their identity hidden may have been leaking identifying information without any awareness.

Mysk responds with fixes

Mysk moved quickly to address the leaks in their own software. Their privacy-focused browser, Psylo, was updated to version 1.3.1 with DNS prefetch hints blocked, WebTransport disabled, and WebAuthn disabled by default.

Users who need passkey functionality or WebTransport can re-enable either feature through per-silo toggles in the app’s settings, giving them granular control over the trade-off between functionality and privacy.

The team also alerted the Tor Project and the developers of Onion Browser on iOS, both of whom are expected to release their own mitigations in upcoming updates.

However, the fundamental issue remains: these are not bugs in individual apps but architectural decisions in WebKit itself. A comprehensive fix requires Apple to modify WebKit so that DNS prefetching, WebAuthn-related requests, and WebTransport all respect the user’s proxy configuration by default.

A pattern of privacy tensions

This episode fits into a broader pattern of tension between Apple’s privacy marketing and the technical realities of its platforms. The company has spent years positioning itself as the privacy-respecting alternative to data-hungry competitors, making “Privacy.

That’s iPhone” a central pillar of its brand identity. Yet the WebKit leaks demonstrate how architectural decisions made for performance or convenience can silently undercut those promises without any visible warning to the user.

- Advertisement -

Latest News

Google to retire assistant on mobile devices starting September 4

Gemini, Google's newer AI-powered assistant, to become the default across all supported platforms.

Ola Electric and Axis Energy ink 20 GWh battery storage deal

Ola Electric MoU is an early and emphatic demonstration of the demand Mahashakti can capture from the outset

Samsung unveils next- generation memory technologies

Samsung is determined to extend its lead in the memory market as AI workloads evolve
- Advertisement -
- Advertisement -

More Articles

- Advertisement -