Techcrunch Apple's Private Relay Vulnerability Exposes Users' IP Addresses
Article Content
- •Apple's Private Relay can leak real IP addresses due to flaws in passkey processing.
- •Researchers created a site to test for IP leaks, confirming the vulnerability.
- •Apple has acknowledged the issue but has not committed to a timeline for resolution.
Security researchers have discovered that Apple's iCloud Private Relay can inadvertently expose users' real IP addresses due to flaws in how passkeys are processed. This issue arises when requests bypass Safari's proxy protections, allowing websites to see the user's actual IP address. The researchers, Tommy Mysk and Talal Haj Bakry, created a testing site demonstrating the leak. They opted not to report the issue to Apple due to past experiences with delayed responses. The vulnerability affects users of Private Relay and the OnionBrowser app, but not the official Tor Browser. Apple acknowledged the severity of the issue but has not provided a timeline for a fix. The researchers have developed a private browser called Psylo, which mitigates the IP leak problem.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…