by

Apple’s paid privacy wrapper leaks IP addresses

The Fruity Cargo Cult, Apple’s paid privacy wrapper is leaking real IP addresses through the same browser plumbing forced on iOS users.

According to 404 Media, insecurity experts found a cluster of issues in Job’s Mob’s WebKit engine, the browser tech sitting beneath every iOS browser. The flaws mean iCloud Private Relay can fail to hide a user’s IP address.

A malicious site can exploit the mess to learn a Private Relay user’s real IP address. Some websites may have collected the data accidentally.

The leak hits Job’s Mob’s paid iCloud+ feature and affects OnionBrowser, an iOS app for browsing through the Tor anonymity network. It follows 404 Media’s July report that Hide My Email was exposing real email addresses, despite Job’s Mob knowing about the bug for more than a year before fixing it.

Security researcher Tommy Mysk, who found the problem with security researcher Talal Haj Bakry said: “Any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on.”

The pair built a test site so Private Relay users can check whether they are affected. In 404 Media’s tests, the site returned the real IP address of a user supposedly protected by Private Relay.

For those not in the know, Private Relay is flogged as part of iCloud+ and is meant to mask a user’s IP address while browsing in Safari. Apple’s website says: “Normally when you browse the web, information contained in your web traffic, such as your DNS records and IP address, can be seen by your network provider and the websites you visit. This information could be used to determine your identity and build a profile of your location and browsing history over time.”

The snag is that Private Relay is not a proper virtual private network. It mainly masks Safari browsing, while a typical VPN works at the operating system level and routes traffic from browsers and installed apps.

The researchers said passkeys, which use the WebAuthn standard, can trigger a request from the operating system’s credential service rather than Safari.

“Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path. The destination server sees the device’s real IP address either way,” the researchers wrote.

Because every iOS browser must use WebKit, OnionBrowser gets dragged into the same swamp. “We have already informed them. They said the issue was ‘dire,’ but they let us disclose the issue. They didn’t provide any time when they will address this,” Mysk said.

OnionBrowser creator Mike Tigas said two leaks were “entirely based on how iOS and WebKit work and solely in Apple’s hands. (That’s the part that’s kind of dire).”

Tigas said the third does not apply when OnionBrowser uses its default settings, while the official Tor Browser from the Tor Project is not affected.

 

TOPICS:
404 media  ·  Apple privacy  ·  iCloud Private Relay  ·  iOS security  ·  IP address leak  ·  OnionBrowser  ·  passkeys  ·  Tor Browser  ·  webkit

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews