HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Apple WebKit Flaws Leak IP Addresses Even With iCloud Private Relay

Three WebKit mechanisms (DNS prefetch, WebAuthn fetches, WebTransport) bypass Safari's Private Relay, exposing real IP addresses. This matters for SOC 2 privacy compliance because it creates an undocumented data‑exposure vector that must be monitored and mitigated.

LiveThreat™ Intelligence · 📅 August 07, 2026· 📰 malwarebytes.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Apple WebKit Flaws Leak IP Addresses Even With iCloud Private Relay

What Happened — Researchers identified three WebKit mechanisms—DNS prefetching, WebAuthn‑related fetches, and WebTransport connections—that operate outside Safari’s Private Relay proxy path. When invoked, they send traffic directly to the destination server, revealing the device’s true IP address and DNS resolver despite the user’s expectation of anonymity.

Why It Matters for Compliance & Audit Readiness

  • The leak bypasses a privacy‑enhancing control that many organizations rely on to meet SOC 2 CC6 (Privacy) and CC5 (Confidentiality) requirements.
  • It demonstrates how a seemingly “built‑in” feature can create an undocumented data‑exposure vector, underscoring the need for continuous control monitoring and evidence of mitigation.
  • Verisq’s CookiePLUS Privacy capability helps you capture consent, DSAR readiness, and privacy‑impact evidence that can be used to demonstrate that you have identified and remediated such leakage pathways.

Who Is Affected — Users of Safari on iOS/macOS, any iOS/macOS app that embeds WebKit (Chrome, Firefox, Edge, Brave, Tor‑on‑iOS browsers, etc.), and enterprises that depend on Private Relay for privacy‑by‑design in employee devices.

Recommended Actions

  • Conduct a privacy‑impact assessment (PIA) focused on IP‑address leakage for all WebKit‑based browsers used in your environment.
  • Map the identified leakage to SOC 2 CC6 controls (e.g., “Encrypt transmission of personal data” and “Monitor and log privacy‑related events”).
  • Deploy network‑level egress monitoring to detect unexpected DNS prefetch or WebTransport traffic that bypasses proxy settings.
  • Update internal policies to require verification that any third‑party browser or in‑app web view respects your organization’s proxy or VPN configurations.

Source: Malwarebytes Labs

Technical Notes

  • Attack vector: Vulnerability exploit in WebKit’s internal networking stack; bypass occurs outside the normal page‑loading pipeline.
  • Data exposed: Real IP address, DNS resolver information, and indirect location data.
  • Affected components: Safari Private Relay, any iOS/macOS app using WebKit’s proxy configuration (including third‑party browsers).

Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →