Researchers have discovered that Apple’s iCloud Private Relay, an iCloud+ feature designed to hide users’ IP addresses while browsing in Safari, can be bypassed through a Passkey WebAuthn request, potentially exposing the user’s real IP address. The issue occurs because Passkey credential requests operate outside Safari’s standard browsing connection, so their network traffic is not routed through Private Relay. A website can initiate one of these requests and use the resulting connection to identify the visitor’s real IP address, despite the user browsing through Safari with the privacy feature enabled. Researchers Talal Haj Bakry and Tommy Mysk traced the leak to three WebKit features, meaning some third party and Tor based browsers using WebKit’s proxy relay may also be affected. They did not privately report the issue to Apple, citing previous delays and disagreements over the impact of reported vulnerabilities, but published a proof of concept website that lets users check whether...
Related
Recent reports reveal Apple’s iCloud Private Relay is leaking users’ real IP addresses
Researchers have discovered that Apple’s iCloud Private Relay, an iCloud+ feature designed to hide users’ IP addresses while browsing in Safari, can be bypassed through a Passkey W...
Proton’s privacy-focused AI Lumo can now generate interactive charts and visuals in chat
Lumo introduces the ability to generate charts, graphs, and custom visuals directly within chat conversations. Users can upload datasets, spreadsheets, or documents, paste structur...
Cloudflare is developing programmable wallets for AI agents to pay for online services
Cloudflare has introduced cloudflare.pay, a persistent identifier system for AI agents that handle online transactions. Users can reserve human readable addresses such as research....