securityonline.info 8/6/2026, 6:42:22 AM · external

Apple iCloud Private Relay bug leaks IP via WebKit CVE-2026-63077

Apple iCloud Private Relay bug leaks IP via WebKit CVE-2026-63077
Developing story vulnerability 10 articles tracked
JetBrains TeamCity deserialization flaw (CVE-2026-63077) exploited in the wild
CyberSIXT Evidence Panel
Primary Source mysk.blog
CISA KEV Listed in KEV
Patch Patch Available

THE content discusses a critical vulnerability (CVE-2026-63077) affecting Apple's iCloud Private Relay, which is part of their paid iCloud+ service. This feature is designed to enhance user privacy by routing traffic through dual relay nodes to conceal actual IP addresses. However, it does not function as a complete VPN and can expose users' real IP addresses during authentication with passkeys. The flaw is due to the WebKit architecture, which bypasses the Private Relay, thus leaking IP addresses and DNS details. Security researchers recommend using a system-wide VPN for better privacy until Apple resolves the issue.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline