Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Overview
Researchers have discovered a vulnerability in Apple's iCloud Private Relay, a tool designed to protect user privacy by masking IP addresses when using Safari. This feature, which uses a dual-hop system to route traffic through two relays, can potentially expose users' real IP addresses due to certain bypasses in the WebKit proxy. This issue affects anyone using iCloud Private Relay on devices running iOS 15 or later. The revelation raises concerns about user privacy, as the very purpose of the service is to prevent third parties, including Apple, from tracking user locations. Users should be aware of this flaw and consider additional privacy measures until a fix is implemented.
Key Takeaways
- Affected Systems: Apple iCloud Private Relay on iOS 15 and later
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from
Impact
Apple iCloud Private Relay on iOS 15 and later
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Not specified
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to iOS, Apple, Vulnerability.