• Salah Abdullah Al-attar - Editor-in-Chief

  • ع

A new vulnerability: Apple's Private Relay feature reveals users' IP addresses..

Two cybersecurity researchers have discovered a vulnerability affecting Apple's Private Relay security feature. This vulnerability could, in some cases, expose a user's IP address while browsing the web, despite the feature being designed to mask this data and enhance privacy.


Researchers Talal Hajbakri and Tommy Mysk explained that the issue stems from the WebKit browser engine used in Safari and all iOS browsers, causing the feature to malfunction in certain situations.



What exactly is Private Relay?


Private Relay is a paid privacy feature available to Apple iCloud+ subscribers. It aims to hide a user's real IP address while browsing in Safari, limiting the ability of websites and internet service providers to track their activity.


While similar to VPN services, it's not a complete replacement. Its protection is limited to Safari browsing and some web connections; it doesn't secure all applications or device-wide data traffic, nor does it offer features like changing the user's geographic location.


What's the new vulnerability?


According to researchers, the vulnerability arises when using passkeys, a modern method of logging in without passwords. In this case, the device sends the authentication request outside the browser, whereas Private Relay's protection is limited to browsing within Safari and doesn't provide comprehensive system-wide data protection like traditional VPNs.