← Latest briefing

Technology

Apple quietly addresses iCloud Private Relay IP address leak with iOS update

A vulnerability that exposed users' IP addresses has reportedly been resolved, though Apple did not include it in its security release notes.

The short version

  • Apple has reportedly patched an iCloud Private Relay vulnerability in iOS 26.6.1 and corresponding operating system updates that previously allowed users' IP addresses to leak.
  • The issue, first identified earlier in August, allowed IP addresses to be exposed under three specific circumstances despite the privacy feature being active.
  • Although the fix appears to be active, Apple did not formally list the patch in its security release notes for the update.

Key facts

  • The iCloud Private Relay vulnerability, which leaked users' IP addresses even when the security feature was turned on, was discovered in August by developers Talal Haj Bakry and Tommy Mysk.[CNET]
  • The leak affected traffic on Apple's Safari browser and applications utilizing the company's WebKit framework.[CNET]
  • Developer Tommy Mysk reported on X that the fix appeared in Apple's 26.6.1 operating system releases, though Apple did not document the fix in its official security release notes.[CNET]
  • The vulnerability previously led to a lawsuit against Apple by the Clarkson Law Firm.[CNET]

What remains uncertain

  • Apple has not publicly commented on the update, leaving the official explanation for why the fix was omitted from the security release notes unconfirmed.[CNET]

Sources