
Apple introduced iCloud Private Relay in 2021 as a privacy service designed to let users connect to and browse the web more securely and privately. The service routes web traffic to obscure a user’s IP address from websites and network providers, and was presented as a way to add an extra layer of privacy when using Safari and other supported apps.
Security researchers, however, have warned that iCloud Private Relay may not fully protect users’ IP addresses in all situations. A report cited by media outlets says the problem arises from multiple vulnerabilities in WebKit, the browser engine used by Safari and other iOS apps. Those vulnerabilities could, under certain circumstances, allow websites to discover a user’s real IP address even when iCloud Private Relay is enabled. The report does not establish how widespread the issue is or whether it has been exploited in the wild.
Readers should note the careful language in the report: researchers say Private Relay “may” expose IP addresses “under certain circumstances,” which is different from claiming a complete or universal failure. Headlines that present the issue as total compromise would be sensationalised and ignore the technical nuance about WebKit vulnerabilities. At the same time, the possibility that websites could learn real IP addresses is a legitimate privacy concern. Ordinary users will reasonably seek clarity on how likely such leaks are and whether updates or patches are available. Given the limited public details in the report, it is reasonable to await further confirmation from researchers or from vendors before drawing firm conclusions.
Original article: Apple’s iCloud Private Relay May Expose Users’ Real IP Addresses Due to WebKit Flaws: Report (www.gadgets360.com)
This story was summarised and commented on by AI from the source linked above.