THREE vulnerabilities in WebKit have been discovered that allow users' IP addresses to be exposed despite Apple's iCloud Private Relay feature, which is meant to mask such information. These vulnerabilities include: 1) **DNS Prefetching** - bypasses the proxy to expose DNS servers used, leaking user metadata. 2) **WebAuthn and Passkeys** - enables direct contact with websites outside of the proxy, revealing real IP addresses. 3) **WebTransport** - opens direct connections to servers, exposing users' IP addresses.
These issues affect Safari on iOS and macOS and other apps relying on WebKit. Malwarebytes notes that their VPN is unaffected, and they expect patches from Apple by fall.