Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect. Newly disclosed flaws in WebKit, the browser engine used across iOS, can allow a website to see a visitor’s real IP address. The exposure weakens a privacy safeguard. The issue can be triggered when a site supports, or merely claims to support, passkeys. A device may make a separate network request during sign-in, outside the protected browser route. That creates an opening for a malicious site to collect the address. Researchers Tommy Mysk and Talal Haj Bakry identified the problem, and analysts at 404media verified that the test page returned a supposedly protected user’s real IP address. 404media...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!