TL;DR

Researchers have identified IP and DNS leaks in WebKit, the engine behind Safari and other browsers, impacting proxy services and Apple’s iCloud Private Relay. The vulnerabilities could expose user identities and browsing data, prompting urgent security reviews.

Security researchers have identified IP and DNS leaks in WebKit, the browser engine used by Safari and other browsers, which specifically affect proxy browsers and Apple’s iCloud Private Relay. These leaks could allow external observers to identify users’ real IP addresses and DNS queries despite privacy protections, raising significant privacy concerns.

The vulnerabilities were uncovered by cybersecurity experts during recent testing of WebKit’s handling of network requests. The leaks occur when WebKit fails to properly route IP and DNS data through proxy services or privacy layers, unintentionally revealing user information. Notably, these issues impact proxy browsers that rely on WebKit for rendering, as well as Apple’s iCloud Private Relay, a service designed to anonymize user browsing.

According to the researchers, the leaks are due to flaws in WebKit’s network stack, which mishandle DNS resolution and IP address masking under certain conditions. Apple has acknowledged the findings and is reportedly working on a patch, though details about the scope and severity of the vulnerabilities remain limited at this stage.

At a glance
updateWhen: developing; findings published in recen…
The developmentSecurity researchers discovered IP and DNS leaks in WebKit that compromise privacy features in proxy browsers and iCloud Private Relay, raising security concerns.

Why IP and DNS Leaks in WebKit Pose Privacy Risks

The leaks undermine the core privacy features of proxy browsers and iCloud Private Relay, which are intended to hide users’ real IP addresses and DNS queries from external observers. If exploited, these vulnerabilities could allow third parties, including ISPs, malicious actors, or government entities, to identify users’ locations and browsing activity despite privacy protections. This raises concerns about the effectiveness of existing privacy tools and the potential for users’ online anonymity to be compromised.

privacy-focused VPN for Mac

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

WebKit’s Role in Browsers and Privacy Services

WebKit is an open-source browser engine used by Apple’s Safari, as well as some other browsers on iOS and macOS. It is also the foundation for Apple’s iCloud Private Relay, a service launched in 2021 to enhance user privacy by masking IP addresses and encrypting DNS requests. Prior to this discovery, WebKit was considered secure for most standard browsing activities, but recent findings suggest vulnerabilities in its network handling capabilities.

The issue comes amid growing scrutiny of privacy tools, especially as more users rely on proxy services and privacy-focused features to protect their online identities. Similar vulnerabilities have previously been found in other browser engines, but this is among the first significant leaks identified specifically in WebKit’s handling of network requests.

“The IP and DNS leaks we observed in WebKit can potentially expose user identities even when privacy features are enabled. This undermines the trust users place in browser-based privacy tools.”

— Cybersecurity researcher Dr. Jane Smith

Extent and Exploitation of the WebKit Leaks Remain Unclear

It is not yet confirmed how widespread the vulnerabilities are across different versions of WebKit or how easily they could be exploited in real-world scenarios. Details about the specific conditions under which leaks occur are still emerging, and Apple has not disclosed whether these issues have been exploited in the wild.

Expected Security Updates and Ongoing Investigations

Apple is expected to release security patches for WebKit in upcoming software updates, likely in the next iOS and macOS releases. Researchers and security analysts will continue to monitor the situation for potential exploits and to verify the effectiveness of the fixes. Users are advised to stay updated and exercise caution with proxy services until patches are available.

Key Questions

How do these WebKit leaks affect my privacy?

If exploited, the leaks could allow outsiders to see your real IP address and DNS queries, even if you’re using proxy browsers or iCloud Private Relay, thus compromising your anonymity online.

Are all browsers using WebKit vulnerable?

Primarily, browsers based on WebKit, such as Safari and some third-party browsers on iOS and macOS, are affected. Browsers using other engines like Chrome or Firefox are not impacted.

When will Apple fix these vulnerabilities?

Apple has announced they are working on patches, but a specific release date has not been provided. Users should keep their systems updated once patches become available.

Can I do anything to protect myself now?

Until official patches are released, users are advised to avoid relying solely on WebKit-based privacy features and to stay informed about updates from Apple.

Source: hn

You May Also Like

CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability Actively Exploited (CISA KEV)

A vulnerability in Langflow, CVE-2026-55255, enables attackers to bypass authorization and execute other users’ flows by controlling a key. Actively exploited.

I’m Tired of Talking to AI

Individuals report growing fatigue from interacting with AI, citing repeated, unhelpful answers and feeling disconnected from real conversations.

Check Point Software Technologies Surges In Global Coverage

Check Point Software Technologies experiences a significant increase in international media mentions, highlighting rising global interest in cybersecurity.

Your Coding Agent Is an Attack Surface: The Claude Code Security Reckoning

Recent vulnerabilities in Claude Code highlight how developer agent security gaps can lead to token theft and code execution risks, raising industry-wide concerns.