Recently, two iOS developers who run the privacy research project “Mysk” and the private browser Psylo have reported that certain features in Apple’s WebKit engine can disclose a user’s real IP address even when privacy tools are turned on.

The findings were published on the @mysk_co account on X, and a further elaboration is available on the @psylo_app account.

They’ve also released a public test page which you can find here. You can visit the link on your iPhone, and it’ll show you the possible IP leaks, as I’ve demonstrated below.

WebKit IP leaks.

The problem involves three WebKit behaviors. The first one is “DNS prefetching.” On recent iOS versions, it can skip the proxy and use the device’s normal DNS path instead.

The second loophole involves passkeys. When a site supports passkeys, the system can make a background request that goes straight from the device, which reveals the real IP address. This can happen by just opening the website, without the user needing to sign in. Facebook was given as an example for this.

Finally, there’s WebTransport, which is a newer connection method that can ignore the proxy and expose the real IP address.

These issues affect Safari (based on the WebKit engine) when iCloud Private Relay is enabled. It affects all browsers that use WebKit (which is all browsers on iOS) and route traffic through a proxy, including Psylo, Onion browser, Orion, and more. Since Apple mandates WebKit on all iOS browsers, it’s a problem.

So if you’re a regular user and wondering whether it can happen during normal, everyday browsing, here’s the answer: Yes. According to the researchers, you don’t have to do anything special. Simply opening a website that supports passkeys is enough to trigger an IP leak in some cases.

The other issues (DNS, WebTransport) only occur if the particular site you visit uses these features, but not every site does. 

It’s worth noting that system-wide VPNs that tunnel device traffic aren’t affected by this.

The researchers noted that the investigation began after a Psylo user noticed unexpected DNS leaks. Later, these three mechanisms were identified. They’ve also contacted the Tor project and the developers of Onion.

At the time of writing, it’s unclear whether they’ve reported the issues to Apple, and it also matches their earlier decision to stop submitting bugs through Apple’s bounty program.

Psylo has already addressed the problem in v1.3.1 by blocking DNS prefetching and turning off passkeys as well as WebTransport by default. If users still want to continue using these features, they have the option to turn them back on for individual tabs.

In fact, the previous v1.3 update added stronger anti-fingerprinting protection and also improved performance. More on that here.

Featured image: AI

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Sudhanshu K
192 Posts

I have been a consumer technology enthusiast for over 5 years. Thanks to my experience in software beta testing and product reviews, I've understood and learnt a lot about what bugs and issues bother people, and I spend time trying to simplify their solutions. I cover smartphones, software, social media, apps, AI, and most consumer tech gadgets. Actively pursuing a Computer Science bachelor’s degree. I'm mostly active on Twitter/X (@TechWhirlUlt), drop a DM or tag me if you want to share info or connect!

Next article View Article

Proton might be quietly working on a browser to rival Chrome

It looks like Proton, the Swiss company most people know for its encrypted email, is getting ready to enter the browser market too. The tip-off comes from a job...
Aug 05, 2026 2 Min Read