WebKit IP and DNS leak: how it exposes iCloud Private Relay users

A new report published on the security research blog Mysk describes an IP and DNS leak vulnerability rooted in WebKit, the browser engine that powers Safari and, per Apple's iOS App Store rules, every other browser app on iPhone and iPad, including the third-party proxy browsers people use specifically to hide their location and network activity. The finding is significant because it undermines the very privacy protections these tools promise, revealing a user's real IP address or DNS queries to a website or network observer even when a proxy or VPN-style tunnel is active.
WebKit is Apple's browser engine, and because Apple requires every iOS browser -- whether it is Safari, Chrome for iOS, or a dedicated privacy-focused proxy browser -- to render pages through WebKit rather than its own engine, any leak inside WebKit itself potentially affects every browser on the platform, not just Safari. That single point of failure is what makes this category of bug more consequential on iOS than a comparable flaw would be on desktop, where browsers ship their own independent engines.
The leak the report describes centers on how certain network requests -- particularly ones tied to DNS resolution and specific WebKit APIs -- can bypass the tunnel that a proxy browser or Apple's own iCloud Private Relay sets up. Private Relay is designed to route a user's web traffic through two separate relays so that neither the network provider nor the destination website can see both the user's identity and the site being visited at once.
When a DNS or IP leak occurs, that separation breaks down. A website or a network positioned between the user and the internet can potentially see the user's real IP address, or observe which domains the device is resolving, even though the user believes their traffic is anonymized behind the relay or proxy tunnel. For someone using these tools specifically to avoid being tracked or geolocated, that is precisely the failure mode they were trying to prevent.
This type of leak is not unique to WebKit in the history of browser privacy tools; WebRTC-based IP leaks and DNS prefetching leaks have affected VPN and proxy setups on other browser engines for years, often because a browser feature designed for performance -- resolving a domain name early, or setting up a peer connection before it is needed -- was never audited for how it behaves when the browser is supposed to be tunneling everything through a separate exit point.
What makes proxy browsers on iOS particularly exposed is that they typically cannot swap out WebKit for their own networking stack the way a desktop browser can bundle its own DNS resolver. They are largely limited to configuring what WebKit is given to work with, which means a leak inside WebKit's own request-handling logic is very difficult for a third-party proxy browser to patch around on its own, and effectively requires a fix from Apple.
For iCloud Private Relay users, the exposure is narrower but still notable, since Private Relay is meant to be Apple's own first-party guarantee of this exact kind of protection. A leak that lets a destination site see the real IP address behind Private Relay defeats the specific feature Apple markets as a privacy upgrade for iCloud+ subscribers, rather than a workaround some third-party developer bolted on.
Security researchers who study this category of bug generally recommend a layered response rather than relying on any single tool: pairing a proxy or relay with a DNS provider configured to block leaks, testing for leaks with dedicated browser-based tools before trusting a setup, and treating any privacy tool's guarantee as provisional until independent researchers have tried to break it under real network conditions.
For everyday users who are not privacy researchers, the practical takeaway is more modest: proxy browsers and Private Relay meaningfully raise the bar against casual tracking, but they are not an absolute guarantee against a sufficiently motivated network observer or website, and users with acute anonymity needs -- journalists, activists, people fleeing surveillance -- should treat any single browser-level tool as one layer in a broader defense, not the whole defense.
Apple has a track record of patching WebKit issues once they are responsibly disclosed, and the standard pattern for a leak like this is a fix shipped in a subsequent iOS and Safari update rather than a public acknowledgment of the underlying mechanism. Until such a patch lands, the report's core message is a reminder that "private" and "encrypted" are not automatically the same as "leak-proof," even for tools built specifically to prevent exactly this kind of exposure.
Read next

Why OpenAI's pricey smart speaker uses moving parts to seem "more alive"
OpenAI's reported premium smart speaker will reportedly include moving mechanical parts designed to give the device a sense of personality. The company has confirmed the design is not modeled on an Apple product, according to a new report.

How an Amazon data center could power up the country's most polluting plant
To power a new West Texas data center, Amazon is investing in a natural-gas plant that could become one of the largest single sources of greenhouse gas emissions in the United States. The facility will initially operate outside the state's power grid.

Why AI writing detectors are creating a new era of distrust
AI writing detectors, descended from anti-plagiarism tools, are now casting suspicion on students, writers, and professionals alike. Experts warn the technology is far less reliable than many assume, fueling a broader crisis of trust.

How London's King's Cross went from red-light district to one of the world's top AI hubs
Two decades ago, London's King's Cross was known as one of the city's seediest districts. Today it hosts leading AI labs like DeepMind, illustrating how urban regeneration and tech clustering can reinforce one another.

OpenAI acquires presentation startup NextSlide, folding its team into ChatGPT
OpenAI has acquired NextSlide, a startup that used AI to help users build presentations, with the team now moving to work on ChatGPT. Terms of the deal were not disclosed.