Startups & Technology

Apple Private Relay Vulnerability Exposes User IP Addresses

Apple Private Relay Vulnerability Exposes User IP Addresses

The researchers demonstrated the exploit through a dedicated testing site, which successfully identified real IP addresses during verification tests. According to the findings, the leak originates from three specific features within WebKit, the underlying browser engine powering all iOS web browsers. Unlike a system-wide VPN, Private Relay operates exclusively within Safari, leaving gaps in how network requests are handled.

Bakry and Mysk opted to bypass Apple’s formal disclosure process entirely. Citing past frustrations with the company’s security reporting channels, they alleged a history of delayed responses and denials regarding the severity of previously reported flaws. Apple has not yet provided a statement regarding these claims. Meanwhile, the researchers have already implemented patches within their own browser, Psylo, to block the specific WebKit behaviors that lead to these leaks.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!