Understanding iCloud Private Relay Limits
Apple includes iCloud Private Relay as a privacy feature within its paid iCloud+ subscription tier. When users navigate the web via Safari, this service automatically routes traffic through dual relay nodes to conceal real IP addresses and DNS queries. However, Private Relay does not function as a full system VPN. Consequently, it cannot proxy all network traffic originating from the device.
Passkey Vulnerability Exposes Real IP Addresses
Passkeys utilize the WebAuthn standard and store private cryptographic keys directly on local devices or password managers. When a user authenticates using a passkey, the underlying operating system interacts directly with the website. Unfortunately, this authentication exchange occurs entirely outside Safari’s protective proxy umbrella. As a result, the system reveals the user’s authentic IP address and DNS details directly to target servers.
Security researchers explained that WebKit delegates WebAuthn operations to system credential services. These OS services issue direct, encrypted HTTPS requests from the hardware without honoring proxy configurations set by the host application. A malicious webpage can designate any host as its Relying Party Identifier (RPID). Even without direct user interaction, background fetch requests trigger system processing silently without displaying any user interface elements.
Root WebKit Vulnerabilities and Broader Impact
Researchers revealed that this flaw stems directly from core WebKit architectural behavior. In a detailed analysis of how WebKit bypasses proxies causing an iCloud Private Relay IP leak, security experts demonstrated that additional features also expose real user network identifiers. For instance, DNS prefetching features expose authentic DNS servers, while WebTransport protocols leak real IP addresses.
Because these vulnerabilities reside within WebKit itself, third-party browsers operating on iOS suffer from identical exposures. Apple acknowledged the report and confirmed an active investigation. Until official patches arrive, users seeking complete IP and DNS privacy should deploy a system-wide VPN to manage all device traffic effectively.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.