Find notable cyber news and cases, enriched with sources, timelines, and signals.

Apple iCloud Private Relay proxy bypass real IP leak security flaw

Vulnerability
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

Researchers disclosed a WebKit proxy-bypass vulnerability in Apple iCloud Private Relay that can expose a user's real IP address. The flaw affects Safari, other WebKit-based browsers, and devices on iOS, iPadOS, and macOS, weakening the privacy protection the relay is meant to provide. The bypass is triggered by DNS prefetching, WebAuthn Related Origin Requests, and WebTransport, which can send traffic directly from the device instead of through the configured proxy. A VPN can mitigate the leak, and Apple is investigating the issue.

Related Happenings

AirDrop and Quick Share nearby crash and session-bypass flaws security flaw

Vulnerability
H score1 First: 30.06.2026 12:27 Last: 30.06.2026 12:27 Sources 1

About this happening: Nearby attackers can crash AirDrop and bypass Quick Share session checks, exposing Apple, Samsung, and Google Windows file-sharing stacks to local disruption a...

WebKit memory corruption, out-of-bounds write, and use-after-free flaws (multiple vulnerabilities)

Vulnerability
H score1 First: 30.06.2026 10:15 Last: 30.06.2026 10:15 Sources 1

About this happening: WebKit now has four patched vulnerabilities, including CVE-2026-43707, CVE-2026-43716, CVE-2026-43745, and CVE-2026-43715, that can be triggered by malicious...

Apple iOS outdated-device exploit-kit mitigation advisory

Advisory/Mitigation
H score35 First: 20.03.2026 07:16 Last: 20.03.2026 07:16 Sources 1

About this happening: Apple is sending Lock Screen notifications to outdated iPhones and iPads after detecting active web-based attacks, urging users to install updates. The latest noti...

WebKit Same Origin Policy bypass (CVE-2026-20643)

Vulnerability
H score18 First: 18.03.2026 03:06 Last: 18.03.2026 03:06 Sources 1

About this happening: Apple fixed CVE-2026-20643, a WebKit flaw that let malicious web content bypass Same Origin Policy on iPhones, iPads, and Macs. The bug created a cross-origin...

Latest development: 18.03.2026 08:31

Apple released its first round of Background Security Improvements to address CVE-2026-20643 in WebKit, a cross-origin issue in the Navigation API that could bypass the same-origin policy when processing maliciously crafted web content. The flaw affects iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2, and Apple says it was addressed with improved input validation in iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Apple also credits security researcher Thomas Espach with discovering and reporting the shortcoming.

Apple dyld memory corruption flaw actively exploited (CVE-2026-20700)

Vulnerability
H score39 First: 12.02.2026 07:39 Last: 12.02.2026 07:39 Sources 1

About this happening: Apple's CVE-2026-20700 is an actively exploited dyld memory corruption flaw that can enable arbitrary code execution on susceptible Apple devices. The company said...

Timeline

  1. 06.08.2026 14:33 2 articles · 2h ago

    Apple iCloud Private Relay can leak real IP addresses through WebKit proxy bypasses

    Initial Disclosure

    Cybersecurity researchers Talal Haj Bakry and Tommy Mysk disclosed that Apple iCloud Private Relay can leak a user's real IP address because WebKit DNS prefetching, WebAuthn Related Origin Requests, and WebTransport can bypass the configured proxy and send traffic directly from the device. The issue affects Safari, other WebKit-based browsers on iOS and iPadOS, and macOS, and a VPN can mitigate the leak.

    Show sources