A vulnerability in WebKit allows IP addresses and DNS queries to bypass proxy browsers and Apple's iCloud Private Relay, undermining privacy protections for users relying on these services.
Security researchers discovered that WebKit, the engine powering Safari and other browsers, fails to route certain traffic through configured proxies and privacy tools. The flaw enables websites to obtain users' actual IP addresses and DNS queries despite active privacy protections.
The vulnerability affects proxy browsers and iCloud Private Relay, Apple's service designed to mask user identity and browsing activity. Attackers can exploit the leak through specific WebKit behaviors that bypass established privacy protocols.
Affected users include Safari users, iCloud+ subscribers using Private Relay, and anyone relying on proxy-based privacy tools on WebKit-based browsers. The flaw exposes fundamental browsing data that these services specifically aim to protect.
Apple has not yet released a patch. Users concerned about IP and DNS leaks should consider alternative browsers or VPN services until an update becomes available. The discovery highlights recurring challenges in browser security architecture.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.
Healthcare software company Unlimited Technology Systems disclosed a data breach affecting 3.8 million individuals. The breach occurred in October 2025.
Cybercriminals are leveraging artificial intelligence to discover and exploit security weaknesses at unprecedented speeds, creating threats that traditional defenses were never designed to counter.