Apple iCloud Private Relay proxy bypass real IP leak security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Researchers disclosed a WebKit proxy-bypass vulnerability in Apple iCloud Private Relay that can expose a user's real IP address. The flaw affects Safari, other WebKit-based browsers, and devices on iOS, iPadOS, and macOS, weakening the privacy protection the relay is meant to provide. The bypass is triggered by DNS prefetching, WebAuthn Related Origin Requests, and WebTransport, which can send traffic directly from the device instead of through the configured proxy. A VPN can mitigate the leak, and Apple is investigating the issue.
Related Happenings
AirDrop and Quick Share nearby crash and session-bypass flaws security flaw
Vulnerability
H score1
First: 30.06.2026 12:27
Last: 30.06.2026 12:27
Sources 1
About this happening:
Nearby attackers can crash AirDrop and bypass Quick Share session checks, exposing Apple, Samsung, and Google Windows file-sharing stacks to local disruption a...
AirDrop and Quick Share nearby crash and session-bypass flaws security flaw
VulnerabilityAbout this happening: Nearby attackers can crash AirDrop and bypass Quick Share session checks, exposing Apple, Samsung, and Google Windows file-sharing stacks to local disruption a...
WebKit memory corruption, out-of-bounds write, and use-after-free flaws (multiple vulnerabilities)
Vulnerability
H score1
First: 30.06.2026 10:15
Last: 30.06.2026 10:15
Sources 1
About this happening:
WebKit now has four patched vulnerabilities, including CVE-2026-43707, CVE-2026-43716, CVE-2026-43745, and CVE-2026-43715, that can be triggered by malicious...
WebKit memory corruption, out-of-bounds write, and use-after-free flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: WebKit now has four patched vulnerabilities, including CVE-2026-43707, CVE-2026-43716, CVE-2026-43745, and CVE-2026-43715, that can be triggered by malicious...
Apple iOS outdated-device exploit-kit mitigation advisory
Advisory/Mitigation
H score35
First: 20.03.2026 07:16
Last: 20.03.2026 07:16
Sources 1
About this happening:
Apple is sending Lock Screen notifications to outdated iPhones and iPads after detecting active web-based attacks, urging users to install updates. The latest noti...
Apple iOS outdated-device exploit-kit mitigation advisory
Advisory/MitigationAbout this happening: Apple is sending Lock Screen notifications to outdated iPhones and iPads after detecting active web-based attacks, urging users to install updates. The latest noti...
WebKit Same Origin Policy bypass (CVE-2026-20643)
Vulnerability
H score18
First: 18.03.2026 03:06
Last: 18.03.2026 03:06
Sources 1
About this happening:
Apple fixed CVE-2026-20643, a WebKit flaw that let malicious web content bypass Same Origin Policy on iPhones, iPads, and Macs. The bug created a cross-origin...
WebKit Same Origin Policy bypass (CVE-2026-20643)
VulnerabilityAbout this happening: Apple fixed CVE-2026-20643, a WebKit flaw that let malicious web content bypass Same Origin Policy on iPhones, iPads, and Macs. The bug created a cross-origin...
Latest development: 18.03.2026 08:31
Apple released its first round of Background Security Improvements to address CVE-2026-20643 in WebKit, a cross-origin issue in the Navigation API that could bypass the same-origin policy when processing maliciously crafted web content. The flaw affects iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2, and Apple says it was addressed with improved input validation in iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Apple also credits security researcher Thomas Espach with discovering and reporting the shortcoming.
Apple dyld memory corruption flaw actively exploited (CVE-2026-20700)
Vulnerability
H score39
First: 12.02.2026 07:39
Last: 12.02.2026 07:39
Sources 1
About this happening:
Apple's CVE-2026-20700 is an actively exploited dyld memory corruption flaw that can enable arbitrary code execution on susceptible Apple devices. The company said...
Apple dyld memory corruption flaw actively exploited (CVE-2026-20700)
VulnerabilityAbout this happening: Apple's CVE-2026-20700 is an actively exploited dyld memory corruption flaw that can enable arbitrary code execution on susceptible Apple devices. The company said...
Timeline
-
06.08.2026 14:33 2 articles · 2h ago
Apple iCloud Private Relay can leak real IP addresses through WebKit proxy bypasses
Initial DisclosureCybersecurity researchers Talal Haj Bakry and Tommy Mysk disclosed that Apple iCloud Private Relay can leak a user's real IP address because WebKit DNS prefetching, WebAuthn Related Origin Requests, and WebTransport can bypass the configured proxy and send traffic directly from the device. The issue affects Safari, other WebKit-based browsers on iOS and iPadOS, and macOS, and a VPN can mitigate the leak.
Show sources
- Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses — thehackernews.com — 06.08.2026 14:33
- Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses — thehackernews.com — 06.08.2026 14:33