苹果的私人中继功能可能会向网站和服务暴露你的IP地址

内容来源:https://www.engadget.com/2231360/apple-private-relay-feature-could-reveal-your-ip-address/
内容总结:
苹果“专用代理”功能被曝存在IP地址泄露风险,该功能本应隐藏用户真实IP,但因WebKit引擎漏洞,实际效果并不总是可靠。
据安全研究员Talal Haj Bakry和Tommy Mysk发现,苹果Safari浏览器内置的“专用代理”功能(iCloud+订阅服务的一部分)在实际运行中可能无法完全保护用户隐私,尤其在用户使用“通行密钥”(Passkey)登录网站时,设备会跳出浏览器发起身份验证请求,而“专用代理”仅限于Safari内部生效,无法像真正的VPN那样覆盖全设备流量,因此用户IP地址可能因此暴露给第三方网站或服务。
更令人担忧的是,这一漏洞不仅影响Safari用户。由于所有iOS浏览器都基于WebKit内核,即便是以隐私保护为卖点的浏览器(如OnionBrowser或研究员自研的Psylo)在使用通行密钥时,同样面临IP泄露风险。
研究员已在社交媒体上公开相关发现,并与OnionBrowser及Tor项目团队取得联系,分享技术细节和修复建议。苹果方面向404Media表示已着手调查此事,但研究员指出,苹果修复这类问题往往耗时较长。此前另一个研究团队在2025年年中发现的iCloud“隐藏邮件地址”功能泄露真实邮箱地址的问题,苹果直到整整一年后才推出修复补丁。
研究团队在X平台上发布声明称,他们最初于2026年6月底在Psylo浏览器中收到用户关于DNS泄露的报告,随后调查中又发现了两个相关漏洞,并正以负责任的方式协调披露。
中文翻译:
苹果的“私人中继”功能可能会向网站和服务泄露你的IP地址
该功能本应隐藏你的IP地址,但研究人员发现,由于WebKit的一个问题,它并不总是能正常发挥作用。
苹果的“私人中继”功能本应确保你在Safari浏览器上浏览网页时,没有任何网站甚至苹果公司本身能看到你的IP地址。但据安全研究人员Talal Haj Bakry和Tommy Mysk称,由于苹果浏览器引擎WebKit存在的问题,该功能并不总是能按预期工作。
他们发现的问题之一与通行密钥(passkey)有关,这种新型安全免密码登录方式正日益普及。据404Media报道,当你使用通行密钥登录时,你的设备会在浏览器之外发出认证请求。私人中继是一项绑定Safari的iCloud+功能,它不像真正的VPN那样能在整个设备范围内隐藏你的身份。因此,如果你在Safari上使用通行密钥登录某个网站或服务,就可能导致IP地址泄露。
IP泄露的可能性也不仅限于Safari。由于该问题出在iOS所有浏览器都使用的WebKit上,如果你在其他主打隐私和匿名的浏览器(如OnionBrowser及研究人员自己开发的Psylo浏览器)上使用通行密钥,你的IP地址同样可能暴露给网站和服务。
研究人员在X平台上发布的一篇文章中表示,他们已经联系了OnionBrowser和Tor项目(该浏览器所使用的匿名网络提供方),分享了他们的发现和解决方案。苹果向404Media表示,已经在调查研究人员的报告,但正如研究人员在文章中所说,苹果解决这个问题可能需要很长时间。他们举例提到了iCloud“隐藏邮件地址”功能的问题——另一个研究团队在2025年年中发现了该问题,而苹果直到一年后才推出修复方案,以防止该功能泄露别名背后的真实邮箱地址。
关于负责任披露
我们在WebKit中发现的这些DNS和IP泄露问题,以及如何负责任地处理它们,让我们陷入了一个两难境地。
我们最初是在2026年6月底收到一名用户报告后,意识到Psylo浏览器存在DNS泄露问题的。在我们的调查过程中,我们发现了两处……https://t.co/5kFu0jtUsJ
—— Mysk 🇨🇦🇩🇪 (@mysk_co) 2026年8月5日
英文来源:
Apple's Private Relay feature could reveal your IP address to websites and services
It’s supposed to mask your IP address, but researchers found that it doesn’t always work due to a WebKit issue.
Apple's Private Relay feature is supposed to ensure that no website or even the company itself can see your IP address when you browse the web on Safari. But according to security researchers Talal Haj Bakry and Tommy Mysk, it doesn't always work as intended due to issues with Apple's web browser engine, WebKit.
One of the issues they found is related to passkeys, which are gaining ground as a new secure and password-free login method. As 404Media explains, when you use a passkey to log in, your device makes an authentication request outside of the browser itself. Private Relay is an iCloud+ feature bound to Safari and doesn't shield your identity throughout your device like a real VPN does. So, if you log into a website or a service with your passkey on Safari, it could leak your IP.
The possibility of an IP leak isn't confined to Safari either. Since the issue lies with WebKit that's used on all iOS browsers, your IP could also become visible to websites and services if you use passkeys on other browsers designed for privacy and anonymity, like OnionBrowser and the researchers' own Psylo browser.
The researchers said in a post on X that they have already contacted OnionBrowser and the Tor Project, which provides the anonymity network the browser uses, to share their findings and solutions. Apple told 404Media that it's already investigating the researchers' report, but as the researchers said in their post, it could take a lot of time before the company addresses the problem. They mentioned the issue with iCloud's Hide My Email, for instance, which another research team discovered in mid-2025. Apple didn't roll out a fix, which would prevent the feature from leaking the real email addresses behind aliases, until a year later.
Re: Responsible Disclosure
We found ourselves in a bit of a dilemma with these DNS and IP leaks in WebKit and how to handle them responsibly.
We first became aware of a DNS leak in Psylo in late June 2026 after a user reported it. During our investigation, we found two... https://t.co/5kFu0jtUsJ
— Mysk 🇨🇦🇩🇪 (@mysk_co) August 5, 2026
文章标题:苹果的私人中继功能可能会向网站和服务暴露你的IP地址
文章链接:https://news.qimuai.cn/?post=4735
本站文章均为原创,未经授权请勿用于任何商业用途