Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities SC Media

Apple's Private Relay feature has flaws that can expose user IP addresses

  • What: Apple's Private Relay feature has flaws that can expose user IP addresses
  • Impact: Users' IP addresses can be leaked despite using the feature to hide their identity
Read Full Article →

Application security , Privacy , Endpoint/Device Security Apple’s Private Relay feature has flaws that can expose user IP addresses August 6, 2026 Share By SC Staff (Adobe Stock) Apple's Private Relay, an opt-in feature designed to hide a user's IP address when browsing the internet with Safari, was found to have flaws that can reveal the supposedly hidden IP address. Researchers revealed these issues in a blog post on Tuesday and have created a website where users can test if their IP address is being leaked, even when using Private Relay. TechCrunch verified that the site was able to reveal their real IP address during a test, based on information published by TechCrunch. The vulnerability lies within three features of Apple's WebKit browser engine, which powers all browsers on iOS. Private Relay, exclusive to iCloud+ subscribers, functions only within Safari and is not a system-level privacy tool like a Virtual Private Network (VPN). The researchers, Talal Haj Bakry and Tommy Mysk, opted not to report the issue directly to Apple, citing past experiences with lengthy delays and inconsistent communication. They have, however, implemented mitigations in their own private browser, Psylo, to prevent IP address leaks. Apple has not yet responded to a request for comment regarding these findings. Source: TechCrunch SC Staff Related AI/ML Prompt injection remains top LLM threat, OWASP report finds SC Staff August 6, 2026 Prompt injection attacks continue to present the most dangerous threat from large language models (LLMs), despite the relatively low number of recorded incidents relating to this vector, according to an updated analysis from the Open Worldwide Application Security Project (OWASP). Application security Google mistakenly locks hundreds of Blogger websites SC Staff August 6, 2026 Google locked hundreds of legitimate Blogger websites, with some even being deleted, due to a false positive flagging them for violating the "Malware and Similar Malicious Content" policy, based on information published by Bleeping Computer. AI/ML AI agents caught using social engineering in UK security tests Steve Zurier August 5, 2026 UK researchers found AI agents using deceptive tactics to manipulate humans in security tests. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Anti-Malware Antivirus Software Certificate-Based Authentication Cookie DLL Injection Digital Certificate Extranet Identity Theft Keylogger Registry You can skip this ad in 5 seconds

Share this article