Apple's iCloud+ Privacy Feature Exposes Major Flaw: Users' Real IP and DNS Information at Risk
1 day ago / Read about 0 minute
Author:小编   

Security experts have unearthed a notable privacy loophole in Apple's iCloud Private Relay service. This feature, which comes as part of a paid subscription, is intended to obscure users' IP addresses and DNS details. Yet, three core functionalities—namely, WebAuthn passkey authentication within the WebKit engine, the DNS prefetching capability newly integrated in iOS 26, and the WebTransport data transfer protocol introduced in iOS 26.4—are capable of circumventing the proxy pathway, thereby directly revealing the device's actual network data. This vulnerability spans across all Apple platforms, encompassing iOS, iPadOS, and macOS. Outside the European Union, where the WebKit engine is mandatorily used, the vast majority of third-party browsers on iOS are also susceptible to this security issue, though system-wide VPNs remain unscathed. To substantiate their findings, researchers have established a test website. Apple has confirmed the receipt of the report and has commenced an investigation, but as of now, no immediate solution is available. As a temporary measure, users can deactivate Private Relay and opt for a system-wide VPN to reduce the potential risk.

  • C114 Communication Network
  • Communication Home
7 X 24 Track global technological trends
Hot Topic