
Security researchers have warned that flaws in WebKit, the browser engine underlying Safari and other iOS and iPadOS apps, could in some circumstances let a website discover a user's real IP address…
Security researchers have warned that flaws in WebKit, the browser engine underlying Safari and other iOS and iPadOS apps, could in some circumstances let a website discover a user's real IP address even while iCloud Private Relay is switched on, Gadgets 360 reported. Apple built Private Relay in 2021 specifically to keep users' IP addresses hidden from the websites they visit and from their own network providers. The available report does not say how widespread the underlying flaws are, whether anyone has already exploited them, or how many Private Relay users could be exposed, and nothing in it shows the service has failed across the board.

WebKit sits underneath many of Apple's own apps as well as Safari, so a flaw in it is not confined to the browser alone, which is worth separating from how far the leak actually extends in practice. Nothing in what has surfaced says whether this requires a malicious site built for the purpose, ordinary browsing, or something in between, and that gap sits at the centre of how alarmed a Private Relay user should be. Apple designed the feature specifically to stop a visited site or a network operator from learning a user's address, so a flaw that undermines it touches the one job the tool was built to do. A fix, or Apple's own account of how many people were exposed, would be the marker that turns this from a warning into a measured picture of the damage.
Source: www.gadgets360.com
This brief was synthesised by AI from the source linked above.