Security researchers at Mysk have recently published a discovery regarding a critical vulnerability in Apple's WebKit browser engine. This security flaw causes browsers utilizing proxies, as well as the iCloud Private Relay privacy feature, to leak users' real IP addresses and all DNS queries. This is a concerning finding for anyone relying on anonymity and privacy protection solutions within the Apple ecosystem.
Background & Causes
According to the detailed report published on Mysk's blog, this vulnerability lies deep within the network traffic handling architecture of WebKit—the mandatory engine for all browsers running on iOS and iPadOS, as well as the default Safari browser on macOS. Normally, iCloud Private Relay and proxy services are designed to encrypt all data and route traffic through intermediary servers to effectively conceal user identities. However, an issue arising in the WebKit codebase has inadvertently created technical loopholes, allowing certain real traffic streams to completely bypass this encryption layer.
Technical Analysis & Technology
The core technical issue relates to how WebKit handles direct connection requests from websites, particularly through real-time communication protocols like WebRTC or low-level system routing APIs. When a malicious website or tracking script requests a connection, WebKit sometimes bypasses the system's proxy configuration or ignores iCloud Private Relay settings to perform direct DNS queries through the local network. This abnormal behavior exposes the local Internet Service Provider (ISP) DNS server, thereby leaking the device's real IP address. The lack of synchronization between the operating system-level network routing mechanism and WebKit's separate network handler is the root cause of this severe security flaw.
Expert Opinions & Assessments
Security researchers at Mysk have issued a strong warning that this vulnerability severely undermines the core value of iCloud Private Relay—a premium security feature heavily promoted by Apple as offering absolute privacy protection for iCloud+ subscribers. Independent security analysts also note that Apple's mandate requiring third parties to use WebKit on iOS exacerbates the scale of this issue, as users cannot switch to a truly independent browser engine to mitigate the risk. As of now, Apple has not provided any official response or announced a specific patching schedule.
Impact & Future
This IP and DNS leak incident via WebKit once again sparks intense debate over Apple's monopolistic browser engine policy on its mobile devices. For tech users in Vietnam and worldwide, real IP address leaks can lead to risks of location tracking, browsing behavior monitoring, and a significant reduction in personal data security effectiveness. Experts advise readers to temporarily refrain from performing highly sensitive tasks that require high anonymity on WebKit-based browsers until Apple officially releases a security patch for this vulnerability.