Junglewise Threat Intelligence

CVE-2026-65355: Apple iOS, iPadOS, and macOS information disclosure in Authentication Services with Private Relay

CVE-2026-65355 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Technologies: Apple macOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's Private Relay feature, which masks user IP addresses when browsing, contains a flaw that allows websites to determine a user's real IP address despite the privacy protection being enabled. This information disclosure affects iOS, iPadOS, macOS, and visionOS devices. Exploitation could reveal user location and browsing activity patterns, undermining the privacy guarantees users expect from this paid security feature.

Technical details

The vulnerability is an information disclosure issue in the Authentication Services component caused by improper state management. A website can determine a user's real IP address even when Private Relay is enabled, which should prevent this kind of network-level tracking. The attack vector is network-based and requires no special privileges—a user simply visiting a malicious or compromised website is sufficient. An attacker can use this to identify the actual IP address and location of users who believe they are anonymized. The issue is addressed in iOS 18.7.10 and later, iPadOS 18.7.10 and later, iOS 26.6.1 and later, iPadOS 26.6.1 and later, macOS Tahoe 26.6.2 and later, and visionOS 26.6.1 and later.

Affected products

  • Apple iOS before 18.7.10 and before 26.6.1
  • Apple iPadOS before 18.7.10 and before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple visionOS before 26.6.1

Timeline

  • 2026-09-14: disclosed: CVE-2026-65355 disclosed and documented in Apple security advisories
  • 2026-08-17: patched: iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 released with fix

References

Related threats