Overview
- Security researchers discovered three WebKit behaviors—DNS prefetching, WebAuthn/passkey-related OS fetches, and WebTransport—that can reveal a device’s real IP address or DNS data even when users browse through proxy apps or iCloud Private Relay.
- The issues were revealed after a Psylo user reported odd DNS activity and researchers published a proof-of-concept test site that demonstrates each leak and lets users check their exposure.
- Psylo issued an update that disables the implicated WebKit features as a temporary mitigation and Onion Browser’s highest security setting blocks the WebTransport vector by turning on Lockdown Mode.
- Apple has been notified and told reporters it is investigating the researchers’ report, but no timetable for an upstream WebKit or system patch has been announced.
- System-level VPNs remain effective because they route all device traffic, and the bug highlights how Apple’s rule that all iOS browsers use WebKit creates a single-engine risk to browser privacy that could affect Tor and other proxy apps.