AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Recent security analysis shows that WebKit, the engine behind Safari and other browsers, has IP and DNS leak vulnerabilities. These leaks compromise user privacy in proxy browsers and Apple’s iCloud Private Relay. The issue is confirmed but ongoing investigations are assessing its full scope.

Security researchers have confirmed that vulnerabilities in WebKit, the browser engine used by Safari and other applications, can cause IP and DNS leaks. These leaks impact privacy features like proxy browsers and Apple’s iCloud Private Relay, potentially exposing user IP addresses and DNS queries despite privacy protections.

The vulnerabilities were uncovered during recent security analyses conducted by independent researchers and cybersecurity firms. They demonstrate that WebKit, when handling certain network requests, can inadvertently reveal a user’s real IP address and DNS information, even when using proxy services or privacy features like iCloud Private Relay.

Apple has acknowledged the reports and stated that it is investigating the issues. The leaks are confirmed to affect multiple platforms where WebKit is used, including Safari on macOS and iOS, as well as some third-party browsers based on WebKit. Experts warn that these leaks could undermine the privacy guarantees offered by proxy services and iCloud Private Relay, which are designed to mask user identities online.

At a glance
updateWhen: developing; disclosures made in late Oc…
The developmentSecurity researchers have identified IP and DNS leaks in WebKit that affect proxy browsers and iCloud Private Relay, potentially exposing user identities.

Why WebKit IP and DNS Leaks Pose Privacy Risks

The leaks are significant because they undermine core privacy features relied upon by millions of users. Proxy browsers and iCloud Private Relay are intended to hide users’ real IP addresses and DNS queries, protecting against tracking and surveillance. The vulnerabilities could allow malicious actors or third parties to identify users’ locations and browsing habits, reducing the effectiveness of these privacy tools.

This development raises broader concerns about the security of WebKit, which powers a large portion of the web browsing ecosystem, including many third-party browsers. It emphasizes the importance of timely security patches and the need for ongoing scrutiny of browser engine vulnerabilities.

Amazon

VPN with IP leak protection

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on WebKit and Privacy Protections

WebKit is an open-source browser engine primarily developed by Apple and used in Safari, as well as other browsers and applications on macOS and iOS. Over recent years, WebKit has integrated various privacy features, including support for proxy browsers and Apple’s iCloud Private Relay, which aims to anonymize user traffic and prevent tracking.

Previous security assessments have identified vulnerabilities in WebKit, but the recent findings highlight a new class of leaks specifically related to IP and DNS information. These issues have been under active investigation since early October 2023, with researchers publishing preliminary findings that prompted Apple to acknowledge the problem.

Lang Tools CLT-2 100 PSI Cylinder Leakage Tester with 2 Gauges, One Size

Lang Tools CLT-2 100 PSI Cylinder Leakage Tester with 2 Gauges, One Size

  • Cylinder Leakage Testing: Measures engine cylinder air retention
  • Includes 2 Gauges: Two gauges for accurate readings
  • One Size Fits All: Universal compatibility for different engines

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent and Severity of the WebKit Leaks Still Unclear

While the leaks are confirmed by security researchers, the full extent of the vulnerabilities and their potential for exploitation are still being evaluated. It is not yet clear how many users are affected or whether current patches fully mitigate the issue. Apple has not released specific technical details or a timeline for a fix.

Amazon

privacy-focused browser extensions

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Apple and Developers Working on Security Updates

Apple is expected to release security updates for Safari and WebKit in the coming weeks to address these leaks. Researchers are continuing to analyze the vulnerabilities to determine if additional patches are needed. Users relying on proxy browsers or iCloud Private Relay should stay alert for updates and follow best practices for online privacy until fixes are deployed.

Amazon

secure proxy browser

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How do these WebKit leaks affect my privacy?

The leaks can expose your real IP address and DNS queries, potentially revealing your location and browsing activity even when using privacy tools like proxy browsers or iCloud Private Relay.

Are my devices vulnerable now?

The vulnerabilities are confirmed to affect devices running vulnerable versions of WebKit, including Safari on macOS and iOS. Patches are forthcoming, but users should monitor updates from Apple.

What should I do to protect myself?

Keep your device’s software up to date, avoid relying solely on existing privacy features until patches are released, and consider using additional privacy tools or network configurations.

Will Apple fix this quickly?

Apple has acknowledged the issue and is working on security updates. The timeline for fixes remains uncertain, but updates are expected within the next few weeks.

Could this vulnerability be exploited by hackers?

Potentially, yes. If exploited, it could allow malicious actors to identify users despite privacy protections. The severity depends on the exploit’s scope and deployment.

Source: hn

You May Also Like

Keyv And Friends Compromised In Active Shai-Hulud Supply Chain Attack

Hackers compromised Keyv and associated entities in an ongoing supply chain attack targeting Shai-Hulud, raising security concerns across the sector.

US Military’s Cyber Command Unit Grapples With Cluster Of Deaths By Suicide

US Cyber Command reports a cluster of suicides among its personnel, raising concerns about mental health and support systems in military cyber units.

Judge approves $46.75 million payout for 23andMe data breach victims

A judge has approved a $46.75 million payout for victims of the 23andMe data breach, affecting thousands of users and raising privacy concerns.

Exploit Brokers Pay $500K For WordPress RCEs. I Found One With GPT5.6 And $25

Exploit brokers are reportedly paying up to $500,000 for remote code execution vulnerabilities in WordPress, with one broker offering $25 for a GPT5.6-based exploit.