Executive brief
Apple's Private Relay service, which masks a user's IP address when browsing, can be bypassed by a malicious website to reveal the user's true IP address. This undermines the privacy protection that users expect when using Private Relay, potentially exposing their location and identity to websites despite enabling privacy protections.
Technical details
The vulnerability is an information disclosure issue in the Authentication Services component affecting Safari's Private Relay feature. It stems from improper state management that allows a website to determine a user's IP address even when Private Relay is enabled. The attack vector is network-based and requires user interaction (visiting a malicious website). No authentication or special privileges are required on the attacker's side. Apple has patched the issue in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 26.6.1 through improved state management.
Affected products
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 26.6.1
Timeline
- 2026-09-14: disclosed
- 2026-08-17: patched: Patches released for iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1