Apple users who use iCloud Private Relay for enhanced online privacy might not fully secure their location data. New vulnerabilities in WebKit, the engine used across iOS devices, allow websites to reveal real IP addresses. It can be activated when a site supports passkeys or claims to do so, leading to additional network requests outside the protected browser route.

Researchers Tommy Mysk and Talal Haj Bakry identified this issue, while analysts at 404media confirmed that the test page provided their actual IP address. The researchers found that using WebAuthn for passkeys can bypass Safari's proxy route by calling the operating system’s credential service directly.

Users will only see a normal passkey prompt, and malicious operators could create pages to log visitors' addresses without requiring them to install software or open documents. An address leak could help stalker, advertisers, fraud groups, or targeted attackers identify the user behind their browsing session. Impact on Anonymous Browsing The researchers discovered that underlying WebKit behavior also affects OnionBrowser, an iOS application utilizing Tor's anonymous network.

OnionBrowser creator Mike Tigas highlighted that two of the reported leaks are within Apple's control, while another does not impact the app under default settings. Site owners should avoid treating a detected address as a reliable identity signal, while security teams can review passkey flows and privacy claims.