Index  ›  defence  ›  TechRadar
defence · TechRadar ↗

Apple

TechRadar Published Aug 6, 2026 Reviewed Aug 6, 2026 ✓ Reviewed by citations.press editors
Apple
Talal Haj Bakry and Tommy Mysk found three WebKit features that bypass the proxy configuration and send traffic directly from the device instead.
3 features · WebKit features Talal Haj Bakry and Tommy Mysk, security researchers
DNS prefetching in WebKit, available since iOS 26.0, resolves hostnames through the device’s normal DNS path, revealing the user’s real DNS servers instead of the proxy’s.
26 iOS version · DNS prefetching Talal Haj Bakry and Tommy Mysk, security researchers
WebAuthn Related Origin Requests in WebKit, available since iOS 18.0, cause the operating system’s credential service to fetch a validation file directly from the device, exposing the device’s real IP address.
18 iOS version · WebAuthn Related Origin Requests Talal Haj Bakry and Tommy Mysk, security researchers
WebTransport in WebKit, available since iOS 26.4, opens a direct HTTP/3 connection and bypasses the proxy, exposing the device’s real IP address.
26.4 iOS version · WebTransport Talal Haj Bakry and Tommy Mysk, security researchers
Apple, according to 404 Media, said it was looking into the research report on the WebKit vulnerability.
404 Media, news outlet

WebKit, Apple’s engine that powers all web browsers in its ecosystem, contained multiple flaws that helped leak the IP addresses of users who paid to keep them hidden.

This is according to security researchers Talal Haj Bakry and Tommy Mysk who noted they had found “three WebKit features that bypass the proxy configuration and send traffic directly from the device instead,” they wrote.

DNS prefetching resolves hostnames through the device’s normal DNS path, which reveals the user’s real DNS servers instead of the proxy’s. Available since iOS 26.0; WebAuthn Related Origin Requests make the operating system’s credential service fetch a validation file directly from the device. This exposes the device’s real IP address. Available since iOS 18.0; WebTransport opens a direct HTTP/3 connection and bypasses the proxy, which also exposes the device’s real IP address. Available since iOS 26.4," the researchers said.

While the bugs are in WebKit, the leaks come via Private Relay - a privacy feature available with iCloud+ that hides a user’s IP address and encrypts Safari web traffic. Private Relay does not work like a VPN, and does not mask the traffic flowing through other apps and programs - it just handles browser traffic.

Since WebKit is mandatory for all browsers running in Apple’s ecosystem, the vulnerability affects all of them. Some, including Tor and Mysk’s very own Psylo browsers, have already issued fixes.

Apple, on the other hand, has not yet confirmed a fix, or even that it was working on one. It did say, according to 404 Media, that it was looking into the research report.

The researchers built a dedicated website where users can check if Private Relay is working as intended or still leaking the actual IP address into the wild.

➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Please logout and then login again, you will then be prompted to enter your display name.

This article was originally published by TechRadar ↗. citations.press indexes the source-backed facts above and links to the original. Something wrong? Corrections policy · Report an error