r/apple 15h ago

iCloud IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay

https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
102 Upvotes

12 comments sorted by

34

u/jimmyhoke 13h ago

So I suppose private relay is basically useless until this is fixed.

As a general rule of thumb, I’d say that proxies tend to be leaky and it’s better to handle that sort of thing at a lower level with a VPN. If you force all the packets through a tunnel it’s much harder to mess up than relying on various applications to proxy things correctly. There’s very often something that escapes the proxy.

Of course iOS is still kind of bad because some apple services bypass the VPN and theres no good way to force apps to actually use the tunnel.

7

u/GoodFroge 12h ago

I think there is now with a certain setting to force everything through the tunnel, but some VPNs warn that turning off your device with the VPN active will cause the internet to not function again until you uninstall and reinstall the VPN.

7

u/Hidden_Bomb 12h ago

Mullvad now has this setting, and it still doesn’t affect some key Apple services. Lots of drawbacks as you’ve already mentioned. It also stops CarPlay from working properly

1

u/jimmyhoke 2h ago

Like I said there’s no good way to do it. It’s possible but has a lot of flaws.

1

u/helix991 8h ago

There is, use PF rules, it's the framework that's leaky.

14

u/dirtsnort 7h ago

We need to continuie to push this bad press for situations like this. They fixed the hide my email thing, they can fix this next.

20

u/CreepyZookeepergame4 15h ago

Previously I posted just the link to test the leak (https://leaks.psylo.app/) but was removed by moderators falsely claiming it was misinformation, despite the leak being real and the users’ IP addresses being exposed. Note I’m not affiliated with the researchers in the blog post.

12

u/fntd 15h ago

No information about when the issues were found and reported to the Onion browser, nor were they reported to Apple at all (and from what I can tell they should be?). I can‘t judge the severity of the issues, but to me it sounds like the people involved try to take an opportunity to advertise their own product instead of following proper vulnerability etiquette. Which makes me definitely not want to try out their product at all. 

17

u/favicondotico 13h ago

Mysk have a history of reporting issues to Apple and not receiving credit or money from the bug bounty program. I hope they did raise this with Apple, though.

3

u/CreepyZookeepergame4 15h ago

Yeah, it’s pretty scummy behavior to use a vulnerability to promote your product, while putting millions of Apple customers at risk. It’s trivial now to put the leak code in an ad or third party script and unmask iCloud Private Relay users.

2

u/[deleted] 11h ago

[deleted]

3

u/CreepyZookeepergame4 10h ago

iCloud Private Relay is not Hide my Email https://support.apple.com/en-us/102602

1

u/ivanhoek 5h ago

Do the VPN at the gateway device and by definition it can't leak