Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Apple’s iCloud Private Relay, touted as a robust tool for protecting user anonymity online, has been found vulnerable to exploitation through WebKit proxy bypasses. This means that even when users are connected to iCloud Private Relay, their real IP addresses can be exposed under certain conditions. The issue affects millions of Apple device owners worldwide who rely on the service for secure browsing.

The flaw lies in the way WebKit, a browser engine used by Safari and other Apple applications, interacts with iCloud Private Relay. When a user visits a website that uses a proxy server to bypass WebKit’s built-in security features, their real IP address can be revealed. This happens because WebKit does not properly enforce the use of iCloud Private Relay even when it is enabled for an entire session. As a result, users may unknowingly expose themselves to tracking and surveillance.

The vulnerability affects not just individual users but also organizations that trust Apple’s security measures to protect their sensitive information. Many companies rely on cloud services like iCloud Private Relay to shield their employees’ online activities from prying eyes. The fact that this service can be bypassed raises serious concerns about data protection and compliance with regulatory requirements.

To understand how this works, consider the concept of “cross-domain privilege escalation.” When a user accesses multiple websites or applications within a single browsing session, their device establishes connections to different servers. Each connection has its own set of permissions and security settings. If an attacker can exploit weaknesses in these settings, they may be able to escalate privileges and gain access to sensitive information. In the case of iCloud Private Relay, the bypass allows attackers to map cross-domain privilege escalation routes at key choke points – essentially creating a backdoor for malicious actors.

The revelation raises questions about Apple’s commitment to user security. With millions of users trusting iCloud Private Relay to protect their online identities, it is unacceptable that such vulnerabilities exist in the first place. Furthermore, the fact that this issue has not been addressed through software updates or patches highlights concerns about the effectiveness of Apple’s bug-tracking and remediation processes.

To protect yourself from potential exposure, consider disabling Safari’s built-in security features whenever you use iCloud Private Relay. Although this may introduce some inconvenience, it is a temporary measure to prevent accidental IP address exposures. More importantly, users should remain vigilant and report any suspicious activity or anomalies in their browsing behavior. By staying informed and proactive, we can mitigate the risks associated with such vulnerabilities and maintain our online security integrity.


Source: The Hacker News — 2026-08-06