Security researchers have discovered a significant flaw in Apple's iCloud Private Relay feature, which is designed to mask users' IP addresses. The vulnerability, stemming from issues within Apple's WebKit browser engine, allows websites to potentially access a user's real IP address, even when Private Relay is active. This occurs particularly when using passkeys for authentication, as these requests are made outside the browser's protected path. The flaw also affects other iOS browsers that rely on WebKit, including OnionBrowser, and Apple has stated it is investigating the report. AI
IMPACT Potential erosion of trust in privacy features could impact user adoption of AI-driven services that rely on user data.
RANK_REASON The cluster reports a bug in a specific privacy feature of a widely used product, impacting user security and privacy.
Read on Mastodon — mastodon.social →
- 404 Media
- Apple Inc.
- iCloud Private Relay
- iOS
- OnionBrowser
- passkeys
- Safari
- Talal Haj Bakry
- Tommy Mysk
- Tor
- IP address
- WebKit
- Hide My Email
- iCloud
- Private Relay
- The Tor Project, Inc
AI-generated summary · Google Gemini · from 6 sources. How we write summaries →