Particle.news
Download on the App Store

WebKit Flaws Let iPhones and Macs Leak Real IPs Despite Proxies

They show browser-engine behavior can bypass Safari proxies, exposing gaps in Apple’s platform privacy protections.

Overview

  • Security researchers discovered three WebKit behaviors—DNS prefetching, WebAuthn/passkey-related OS fetches, and WebTransport—that can reveal a device’s real IP address or DNS data even when users browse through proxy apps or iCloud Private Relay.
  • The issues were revealed after a Psylo user reported odd DNS activity and researchers published a proof-of-concept test site that demonstrates each leak and lets users check their exposure.
  • Psylo issued an update that disables the implicated WebKit features as a temporary mitigation and Onion Browser’s highest security setting blocks the WebTransport vector by turning on Lockdown Mode.
  • Apple has been notified and told reporters it is investigating the researchers’ report, but no timetable for an upstream WebKit or system patch has been announced.
  • System-level VPNs remain effective because they route all device traffic, and the bug highlights how Apple’s rule that all iOS browsers use WebKit creates a single-engine risk to browser privacy that could affect Tor and other proxy apps.