Technology
Apple quietly addresses iCloud Private Relay IP address leak with iOS update
A vulnerability that exposed users' IP addresses has reportedly been resolved, though Apple did not include it in its security release notes.
The short version
- Apple has reportedly patched an iCloud Private Relay vulnerability in iOS 26.6.1 and corresponding operating system updates that previously allowed users' IP addresses to leak.
- The issue, first identified earlier in August, allowed IP addresses to be exposed under three specific circumstances despite the privacy feature being active.
- Although the fix appears to be active, Apple did not formally list the patch in its security release notes for the update.
Key facts
- The iCloud Private Relay vulnerability, which leaked users' IP addresses even when the security feature was turned on, was discovered in August by developers Talal Haj Bakry and Tommy Mysk.[CNET]
- The leak affected traffic on Apple's Safari browser and applications utilizing the company's WebKit framework.[CNET]
- Developer Tommy Mysk reported on X that the fix appeared in Apple's 26.6.1 operating system releases, though Apple did not document the fix in its official security release notes.[CNET]
- The vulnerability previously led to a lawsuit against Apple by the Clarkson Law Firm.[CNET]
What remains uncertain
- Apple has not publicly commented on the update, leaving the official explanation for why the fix was omitted from the security release notes unconfirmed.[CNET]