Overview
- Researchers Tommy Mysk and Talal Haj Bakry published a proof-of-concept this week that demonstrates DNS prefetching, WebAuthn related‑origin requests for passkeys, and WebTransport can send network requests outside WebKit’s proxied path.
- Because Apple requires WebKit for iOS browsers, the bugs affect Safari and many third‑party proxy and Tor‑style browsers that rely on WebKit’s proxy APIs.
- The most serious vector is WebAuthn passkey validation, where the operating‑system credential service fetches a verification file directly from the device and can reveal the real IP without any user prompt.
- Some third‑party browsers such as Psylo and certain Onion Browser settings have shipped mitigations that disable or gate the risky features, and Apple has acknowledged the report and is investigating with a fix targeted for fall 2026.
- For now users who need reliable device‑level IP hiding should use a system VPN, and the disclosure follows a recent July 2026 iCloud+ privacy bug which has increased scrutiny of Apple’s paid privacy services.