
Security researchers say a WebKit flaw may let websites discover users’ real IP addresses even when iCloud Private Relay is enabled. Times Now News reports that passkey-enabled websites can trigger a request…
Security researchers say a WebKit flaw may let websites discover users’ real IP addresses even when iCloud Private Relay is enabled. Times Now News reports that passkey-enabled websites can trigger a request from the device’s credential service, bypassing Private Relay’s proxied path. The researchers identified are Tommy Mysk and Talal Haj Bakry.

The issue may also affect OnionBrowser, a Tor-based browser that uses Apple’s WebKit, according to Times Now News. It says Apple has been informed and plans a fix for autumn 2026. Gadgets 360 cautions that the available information does not show how widespread the problem is or whether attackers have exploited it. Private Relay’s failure is not universal.
The lazy claim that Apple’s privacy service is either perfectly safe or completely broken misses the evidence. The reported passkey pathway could expose an IP address, but there is no proof of widespread attacks or universal failure. Apple should explain which devices and websites are affected, and deliver the promised fix. The practical test is simple: does the update stop passkey-related requests from revealing the real IP address?
Sources (2): gadgets360.com, timesnownews.com
This story was synthesised by AI from the 2 sources linked above.
Updated: this story now draws on 2 sources.