ELSEIF
Your brief EB
300 stories from 73 feeds 75 clusters Refreshed 9 minutes ago next pull 19:35

WEB Signal 434

Mysk: Apple's Private Relay tool can leak users' IP addresses due to issues in Apple's WebKit browser engine, also affecting OnionBrowser, a Tor browser for iOS (Joseph Cox/404 Media)

Researchers at Mysk discovered that Apple's Private Relay can leak users' IP addresses due to flaws in the WebKit engine, a vulnerability that also impacts the OnionBrowser Tor client on iOS.

WHY IT MATTERS

For engineers building privacy-focused iOS apps or relying on Apple's network-level protections, this finding means Private Relay does not guarantee IP anonymity as advertised. Developers who integrate WebKit or depend on its security model must reassume that user IPs may be exposed, and the same flaw extends to Tor-based browsing on iOS, undermining a key privacy tool.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The IP leak originates from issues within Apple's WebKit browser engine, not from the Private Relay service itself.

02

The vulnerability also affects OnionBrowser, a Tor browser for iOS, because it relies on the same WebKit rendering engine.

03

Users who depend on Private Relay for IP privacy may have their real IP addresses exposed despite the feature being enabled.

THE READ

What elseif makes of it.

ORIGINAL ANALYSIS

The discovery by Mysk reveals that Apple's Private Relay, a privacy feature designed to hide users' IP addresses, can be circumvented due to underlying flaws in the WebKit engine. This means the protection is not absolute, and the leak occurs at a lower layer of the browser stack. For engineers, this highlights that privacy features built on top of a compromised foundation can fail silently.

The fact that the same WebKit issues also affect OnionBrowser, a Tor browser for iOS, broadens the impact. Tor browsers are specifically used for anonymity, and a leak in WebKit could expose the user's real IP even when they believe they are fully anonymized. This suggests that any iOS browser using WebKit may be susceptible to similar IP leaks, not just those with explicit privacy features.

Adopting Private Relay or OnionBrowser on iOS now carries a known risk: the IP address may be leaked despite the user's intent. Engineers must consider this when recommending privacy tools to users or when building applications that rely on these protections. The cost is a loss of trust in the privacy guarantees provided by Apple and the Tor project on iOS.

The leak stops working only if Apple patches the WebKit engine or if users avoid using browsers that rely on it. Until a fix is deployed, any network request made through a WebKit-based browser on iOS could potentially expose the user's IP. This undermines the core value proposition of Private Relay and Tor on iOS, forcing engineers to seek alternative privacy measures or wait for a resolution.

Since only one source reported this event, the details are limited to the headline and summary. No technical specifics about the leak mechanism, affected WebKit versions, or mitigation steps are provided. Engineers should monitor for further disclosures from Mysk or Apple to understand the full scope and apply patches when available.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Techmeme Mysk: Apple's Private Relay tool can leak users' IP addresses due to issues in Apple's WebKit browser engine, also affecting OnionBrowser, a Tor browser for iOS (Joseph Cox/404 Media) Open ↗