Overview
- Researchers Tommy Mysk and Talal Haj Bakry disclosed that DNS prefetching, WebAuthn passkey related‑origin requests, and WebTransport can all make direct network calls that bypass the browser proxy and reveal a device’s real IP or DNS data.
- Because Apple requires all iOS browsers to use WebKit, the flaws affect Safari and third‑party proxy or Tor browsers on iPhone and Mac rather than a single app.
- The researchers published a proof‑of‑concept test site that reporters used to verify the leaks and say a passkey-related request can fire from the operating system without visible user interaction, exposing the real IP to the destination server.
- Psylo has pushed mitigations in version 1.3.1 that block DNS prefetching and disable WebTransport and WebAuthn by default, and security guidance from multiple outlets recommends using a system‑level VPN until Apple issues an official WebKit or OS update.
- Apple is investigating the report but has given no public fix timeline; the disclosure follows a July Hide My Email bug and raises fresh questions about the reliability of iCloud+ privacy features and how quickly Apple can patch platform‑level leaks.