{"id":52880,"date":"2026-08-10T15:44:12","date_gmt":"2026-08-10T19:44:12","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=52880"},"modified":"2026-08-10T15:44:12","modified_gmt":"2026-08-10T19:44:12","slug":"webkit-ip-and-dns-leaks-affecting-proxies-and-private-relay","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/08\/10\/webkit-ip-and-dns-leaks-affecting-proxies-and-private-relay\/","title":{"rendered":"WebKit IP and DNS Leaks Affecting Proxies and Private Relay"},"content":{"rendered":"<p><a href=\"https:\/\/mysk.blog\/2026\/08\/04\/webkit-proxy-icloud-private-relay-ip-leak\/\">Talal Haj Bakry and Tommy Mysk<\/a> (<a href=\"https:\/\/infosec.exchange\/@psylo\/117039552203174813\">Mastodon<\/a>, <a href=\"https:\/\/news.ycombinator.com\/item?id=49176697\">Hacker News<\/a>, <a href=\"https:\/\/www.macrumors.com\/2026\/08\/05\/icloud-private-relay-ip-address-leak\/\">MacRumors<\/a>, <a href=\"https:\/\/talk.macpowerusers.com\/t\/private-relay-not-so-private\/46339\">Mac Power Users<\/a>):<\/p>\n<blockquote cite=\"https:\/\/mysk.blog\/2026\/08\/04\/webkit-proxy-icloud-private-relay-ip-leak\/\">\n<p>WebKit-based browsers on iOS and macOS can be configured to route all web traffic through proxy servers, which is how Tor browsers on iOS and our own Psylo work. We found three WebKit features &mdash; DNS prefetching, WebAuthn Related Origin Requests, and WebTransport &mdash; that bypass the configured proxy and send traffic directly from the device, which exposes the user&rsquo;s real network. The same leaks also affect Apple&rsquo;s iCloud Private Relay.<\/p>\n<p>[&#8230;]<\/p>\n<p>It must be noted that VPNs are not affected, since they tunnel the device&rsquo;s entire network traffic at the system level.<\/p>\n<p>[&#8230;]<\/p>\n<p>We&rsquo;ve addressed all three leaks in Psylo 1.3.1[&#8230;] Passkeys and WebTransport have legitimate uses, so both can be re-enabled at any time through per-silo toggles. This keeps Psylo leak-free out of the box, while users who need one of these features on a given site can opt in explicitly, with a clear understanding of the trade-off.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/infosec.exchange\/@psylo\/117043641848577576\">Psylo<\/a>:<\/p>\n<blockquote cite=\"https:\/\/infosec.exchange\/@psylo\/117043641848577576\">\n<p>In an ideal world, we&rsquo;d report the issues to Apple, they acknowledge the issue, and ship a fix in a timely manner. Unfortunately, our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue&rsquo;s impact entirely.<\/p>\n<p>We weren&rsquo;t willing to wait months, or upwards of a year, sitting on bugs that undermine the core privacy guarantees of Psylo and iOS Tor browsers while saying or doing nothing. <\/p>\n<p>[&#8230;]<\/p>\n<p>Should we knowingly leave our users exposed while waiting for a system-level fix? We didn&rsquo;t think that was acceptable or fair to our users. Or should we quietly ship our own mitigations without telling anyone? We didn&rsquo;t think that was acceptable either. Security fixes deserve transparency, especially when they involve tradeoffs.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@psylo@infosec.exchange\/117044214440797753\">Psylo<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@psylo@infosec.exchange\/117044214440797753\">\n<p>Soon after we published the blog, we sent a link to the blog and demo website to Apple in a security report to make them aware of it. Now the report is already in the status &ldquo;We&rsquo;re planning to address the issue you reported.&rdquo; and a fix is planned for Fall 2026 &#x1F92F;&#x1F92F;&#x1F92F;<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@mysk\/117044228843282201\">Mysk<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@mysk\/117044228843282201\">\n<p>It used to take months and months to reach this status. We got there in less than 24h<\/p>\n<\/blockquote>\n\n<p>Running to the press always helps&#8230;<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/07\/02\/hide-my-email-vulnerability-exposes-real-address\/\">Hide My Email Vulnerability Exposes Real Address<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/06\/02\/no-bounty-for-mysk\/\">No Bounty for Mysk<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/06\/17\/psylo-web-browser-1-0\/\">Psylo Web Browser 1.0<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/01\/04\/icloud-private-relay-white-paper\/\">iCloud Private Relay White Paper<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Talal Haj Bakry and Tommy Mysk (Mastodon, Hacker News, MacRumors, Mac Power Users): WebKit-based browsers on iOS and macOS can be configured to route all web traffic through proxy servers, which is how Tor browsers on iOS and our own Psylo work. We found three WebKit features &mdash; DNS prefetching, WebAuthn Related Origin Requests, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-08-10T19:44:18Z","apple_news_api_id":"55074b1d-223c-4927-9c85-2399840fa080","apple_news_api_modified_at":"2026-08-10T19:44:18Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AVQdLHSI8SSechSOZhA-ggA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2098,2154,31,2741,30,2742,2128,2222,355,2782,48,2131,328],"class_list":["post-52880","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple-security-bounty","tag-icloud-private-relay","tag-ios","tag-ios-26","tag-mac","tag-macos-tahoe-26","tag-orion","tag-passkeys","tag-privacy","tag-psylo","tag-security","tag-tor","tag-webkit"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=52880"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52880\/revisions"}],"predecessor-version":[{"id":52881,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52880\/revisions\/52881"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=52880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=52880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=52880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}