#Privacy Vulnerability

Every story tagged Privacy Vulnerability, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

7 stories · open in the command center

  • Security & Privacy9to5MacChance Miller2m

    iCloud Private Relay might be leaking your real IP address, researchers say

    Apple's iCloud Private Relay contains a critical vulnerability that exposes users' real IP addresses when interacting with websites using passkeys, undermining the service's core security promise and affecting iOS users globally since all browsers must use Apple's WebKit engine. This represents a significant privacy and trust risk for organizations deploying Apple devices, particularly those relying on iCloud's privacy protections for sensitive work, and suggests potential vulnerabilities in other Apple privacy features. IT leaders must reassess their reliance on iCloud Private Relay for privacy compliance and consider whether users need additional VPN or network-level protections, especially given Apple's lack of a concrete remediation timeline.

  • Security & PrivacyTechMemeJoseph Cox2m

    Mysk: Apple's Private Relay tool can leak users' IP addresses due to issues in Apple's WebKit browser engine, also affecting OnionBrowser, a Tor browser for iOS (Joseph Cox/404 Media)

    Apple's Private Relay privacy feature contains critical vulnerabilities in its WebKit browser engine that can leak users' real IP addresses, undermining the security assurances that drive customer trust and regulatory compliance efforts. This breach affects not only Apple's own privacy infrastructure but also dependent applications like OnionBrowser, creating cascading security risks across the iOS ecosystem and potentially exposing organizations to liability and reputational damage. IT leaders must recognize that vendor privacy claims cannot be implicitly trusted and require independent validation, particularly when these services form the foundation of organizational security strategies.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    PSA: Apple’s Private Relay can leak your real IP address

    Apple's Private Relay feature, which claims to hide user IP addresses in Safari, contains critical vulnerabilities that allow attackers to circumvent the protection and reveal actual IP addresses through WebKit browser engine flaws. This represents a significant privacy and security risk for iCloud+ subscribers relying on this feature for protection, with researchers bypassing Apple's security without reporting through official channels due to past delays and dismissiveness. IT organizations must reassess their privacy and security posture regarding Apple device management and employee browsing protections, as this vulnerability undermines a key privacy control and highlights broader risks in Safari-based security implementations.

  • Security & PrivacyHacker News3m

    IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay

    Critical privacy vulnerabilities have been discovered in WebKit that allow DNS and IP address leaks to bypass proxy configurations on iOS/macOS browsers and Apple's iCloud Private Relay, affecting all App Store browsers including Tor and exposing users' real network identities despite privacy protections. These three distinct attack vectors (DNS prefetching, WebAuthn requests, and WebTransport) represent a fundamental breach of proxy security that undermines organizational privacy policies and user trust in privacy-focused services. IT leaders must recognize that reliance on application-level proxies or iCloud Private Relay provides incomplete protection, while system-level VPNs remain unaffected, requiring reassessment of mobile privacy and security strategies.

  • Security & PrivacyHacker News3m

    Since Chronium 148, Math.tanh is now fingerprintable to link underlying OS

    Since Chrome 148, a critical fingerprinting vulnerability has emerged where the Math.tanh() function returns slightly different bit-level results across operating systems (Linux, macOS, Windows) due to reliance on platform-specific math libraries, enabling threat actors and anti-bot systems to reliably identify users' underlying OS despite spoofed User-Agents. This represents a significant privacy and security risk for organizations managing browser-based access controls, as attackers can now defeat device verification mechanisms that rely on consistency checks between reported and actual OS signatures. IT leaders must assess the exposure of their web applications and authentication systems to this fingerprinting vector and coordinate with security teams to implement detection mechanisms while monitoring for exploitation by malicious actors.

  • Security & Privacy9to5MacBen Lovejoy2m

    Apple Hide My Email bug seemingly allows 100% of real email addresses to be discovered

    A critical vulnerability in Apple's Hide My Email privacy feature allows attackers to discover 100% of real email addresses associated with masked addresses, representing a significant breach of user privacy protections that Apple has failed to patch despite being notified over a year ago. This incident highlights the risks of relying on third-party privacy solutions and raises concerns about vendor security response times, creating potential exposure for enterprises and users who depend on Apple's privacy commitments. IT leaders must reassess their organization's trust in Apple's privacy guarantees and evaluate whether current security controls adequately protect against compromised identity masking services.

  • Security & PrivacyArs Technica2m

    Apple stops weirdly storing data that let cops spy on Signal chats

    Apple patched a critical security vulnerability that inadvertently stored encrypted Signal message content in push notification logs for up to 30 days, even after message deletion and app removal—enabling law enforcement forensic access that was previously unknown to users. This incident exposes systemic data retention risks across iOS infrastructure beyond this single bug and underscores the tension between device security, law enforcement access, and user privacy expectations. For IT organizations, this highlights the need to reassess how employee-used platforms handle sensitive communications and to implement defense-in-depth strategies rather than relying solely on application-level encryption.

Browse all tags