Apple’s iCloud Private Relay, touted as a secure way to browse the internet privately, has been found to have a critical flaw that can expose real IP addresses through WebKit proxy bypasses. This vulnerability affects millions of users who rely on Apple devices and services for their online security.
The issue stems from a complex interaction between iCloud Private Relay’s built-in proxy server and WebKit, Apple’s web rendering engine. When a user enables the feature, their internet traffic is routed through an intermediate proxy server, which masks their real IP address with a temporary one. However, researchers have discovered that malicious websites can exploit a vulnerability in WebKit to bypass this proxy and access the user’s real IP address.
The implications of this flaw are significant, as it potentially allows attackers to identify individuals who have enabled iCloud Private Relay. This could be used to launch targeted attacks or even track users’ online activities. Apple has not yet released a patch for the vulnerability, leaving affected users exposed until further notice.
One concern is that the WebKit proxy bypass can be triggered by websites using JavaScript code. This means that simply browsing certain websites or interacting with malicious content can expose your real IP address to attackers. The fact that this exploit relies on cross-domain privilege escalation adds complexity, but essentially, it enables hackers to access sensitive information by exploiting differences in how browsers handle different domains.
The potential consequences of this vulnerability are far-reaching and unsettling. For users who rely on Apple devices for their online security, the idea that a supposed protective measure can be bypassed is alarming. Furthermore, the fact that this flaw has gone undetected until now raises questions about Apple’s testing procedures and commitment to user safety.
Apple iCloud Private Relay was designed to provide an additional layer of protection against tracking and surveillance. However, the discovery of this vulnerability highlights the importance of ongoing security research and continuous updates to protect users from evolving threats.
So what can you do? For now, it is recommended that Apple device owners disable iCloud Private Relay until a patch becomes available. This will prevent potential exposure to real IP addresses via WebKit proxy bypasses. Regularly keeping your browser and operating system up-to-date with the latest security patches will also help mitigate risks associated with vulnerabilities like this one.
Source: The Hacker News — 2026-08-06