Close Menu
geekfence.comgeekfence.com
    What's Hot

    Irish SMEs report strong trading

    August 8, 2026

    Deep Learning with R, 2nd Edition

    August 8, 2026

    Deploying Semantic Views on Snowflake

    August 8, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Mobile»Apple looking into passkey bug leaking Private Relay IPs
    Mobile

    Apple looking into passkey bug leaking Private Relay IPs

    AdminBy AdminAugust 5, 2026No Comments3 Mins Read3 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Apple looking into passkey bug leaking Private Relay IPs
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Apple Safari on iPhone stock photo 6

    Edgar Cervantes / Android Authority

    TL;DR

    • Researchers found multiple issues that can expose a user’s real IP despite Private Relay.
    • The problem is tied to passkey-related requests that bypass Safari’s Private Relay path.
    • Apple has acknowledged the report and says it’s investigating.

    Passkeys were supposed to fix our login headaches, but as we recently saw with Google Password Manager, transitioning to passwordless security can expose unexpected cracks in your privacy. Now, Apple is facing similar scrutiny after researchers uncovered a WebKit flaw that lets websites bypass iCloud Private Relay and expose users’ real IP addresses during passkey requests.

    Discovered by security researchers Tommy Mysk and Talal Haj Bakry, the vulnerability centers on how WebAuthn requests interact with iOS (via 404 Media). When a site prompts for a passkey or even pretends to support one, the network request isn’t processed inside Safari’s standard web browser stack. Instead, Apple’s system-level credential service steps in to handle the fetch directly.

    That’s where the problem begins. iCloud Private Relay, which is part of Apple’s paid iCloud+ subscription, only protects traffic that passes through Safari, so these system-level requests bypass it entirely. As a result, a website can see your real IP address, even if you think it’s being hidden. According to the report, users wouldn’t notice anything unusual because the interaction appears to happen as part of a normal passkey flow.

    The fallout isn’t limited to Safari. Because Apple requires every iOS browser to build on its WebKit engine, alternative browsers face the exact same exposure. The flaw even leaks real IP addresses on privacy-focused apps like OnionBrowser on the Tor network. Fortunately, traditional system-wide VPNs remain unaffected because they encrypt traffic at the OS level rather than relying on application proxies.

    To help users verify the behavior, the researchers created a test website that checks whether a device’s real IP address is exposed. Tests reportedly confirm that it returns the actual IP address of a device that has iCloud Private Relay enabled.

    If the findings hold up, they’d mark the second high-profile privacy issue involving an Apple subscription feature in recent weeks, following a flaw in Hide My Email that exposed users’ real email addresses before Apple eventually patched it. Unlike that issue, however, this latest report is still under investigation, so it’s unclear when — or how — Apple plans to address it.

    Thank you for being part of our community. Read our Comment Policy before posting.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Samsung Officially Launches Galaxy Z Fold8 Ultra, Fold8, Flip8, Watch Ultra2 and Watch9 – Samsung Global Newsroom

    August 8, 2026

    Amazon Deals of the Day: Upgrade Your Phone With a Record-Low Price on the Samsung Galaxy A56

    August 7, 2026

    Android Developers Blog: Inside Android Skills

    August 6, 2026

    OpenAI explains what will happen when ChatGPT Atlas shuts down this weekend

    August 4, 2026

    ‘The best Android phone for students’: why I decided to buy the Google Pixel 10a ahead of the Pixel 11 launch

    August 3, 2026

    vivo S2 full specs, Galaxy S27 Pro and Ultra batteries leak, Week 31 in review

    August 2, 2026
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 202572 Views

    The Next Paradigm in Efficient Inference Scaling – The Berkeley Artificial Intelligence Research Blog

    May 16, 202640 Views

    Hard-braking events as indicators of road segment crash risk

    January 14, 202634 Views
    Don't Miss

    Irish SMEs report strong trading

    August 8, 2026

    Almost half (46%) of Irish SMEs say business activity is stronger than it was this…

    Deep Learning with R, 2nd Edition

    August 8, 2026

    Deploying Semantic Views on Snowflake

    August 8, 2026

    Taiwan Investigates Chinese Firms for Poaching Tech Talent

    August 8, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    Irish SMEs report strong trading

    August 8, 2026

    Deep Learning with R, 2nd Edition

    August 8, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.