WebKit Bugs Leak Real IPs, Bypass iOS Proxy Browsers
08 Aug 2026
What happened
Researchers have identified three WebKit features that can bypass proxy configurations on iOS and macOS, exposing users' real IP addresses and DNS servers even when they believe their traffic is anonymized through a proxy browser or Apple's iCloud Private Relay.
WebKit-based browsers can route web traffic through proxy servers, but the report found that DNS prefetching, WebAuthn Related Origin Requests, and WebTransport each create separate paths that sidestep this proxy layer entirely.
The three leak vectors
DNS prefetching resolves hostnames through the device's normal DNS path instead of routing through the proxy, revealing the user's real DNS servers. This directly undermines anonymity assumptions built into proxy browsers and iCloud Private Relay.
WebAuthn Related Origin Requests cause the operating system's credential service to fetch a validation file directly from the device, exposing its real IP address—again, even when a proxy is active.
WebTransport opens a direct HTTP/3 connection that bypasses the proxy altogether, similarly revealing the device's real IP address.
According to the report, all proxy browsers on iOS are affected, including iOS Tor browsers and Psylo, and Apple's iCloud Private Relay is affected by all three leaks. Notably, VPNs are not affected, since they tunnel a device's entire network traffic at the system level rather than relying on browser-level proxy configuration.
Timeline of the underlying features
- Safari 5 (desktop): dns-prefetch support was originally added.
- September 2024 (iOS 18.0 / Safari 18.0): WebAuthn Related Origin Requests were announced.
- September 2025 (iOS 26.0): dns-prefetch support was enabled on iOS.
- December 2025: WebTransport was switched on after previously being disabled.
- March 2026 (iOS 26.4): WebTransport shipped publicly.
- August 2026: The report detailing these leaks and available fixes was published.
How developers are responding
The researchers reached out to the Tor Project and the developers of Onion Browser on iOS about the issues. Two concrete responses stand out:
- Psylo 1.3.1 was released with fixes that block dns-prefetch hints and disable WebTransport and WebAuthn by default. Psylo users can still re-enable WebTransport and WebAuthn through per-silo toggles if a specific website genuinely needs them.
- Onion Browser's "Silver" security level disables WebTransport entirely through Lockdown Mode, protecting users from that particular leak.
What's still unclear
The report leaves several open questions: it's unclear whether Apple has been notified or has any official response or fix planned at the WebKit level. There's no indication of how long these leak vectors have been exploitable in the wild, whether proxy browsers beyond Psylo and Onion Browser have addressed the issues, or whether macOS Safari will see similar mitigations. The real-world scope of impact—how many users may have been affected—also isn't detailed in the source.
Why founders should care
For founders building privacy tools, proxy browsers, or anything relying on WebKit's proxy configuration, this report is likely worth an immediate architecture review. If your product depends on DNS prefetching, WebAuthn Related Origin Requests, or WebTransport without specific mitigations, it may currently be leaking user IP addresses or DNS servers—undermining the core privacy promise of the product.
There's also a plausible product opportunity here: browsers and privacy tools that ship default-secure configurations, or that offer granular per-site toggles (as Psylo now does), may be better positioned to earn user trust than those relying on WebKit defaults. Given that VPNs are unaffected by these specific leaks, startups in the VPN space may find this reinforces messaging around system-level tunneling as a more complete privacy guarantee compared to browser-level proxies. Founders evaluating build-vs-partner decisions in the privacy-tech space should weigh this distinction carefully.