Impact
An information disclosure vulnerability allows a website to determine a user’s real IP address even when Private Relay is enabled. The flaw stems from improper state management, enabling a malicious site to read the IP that should be hidden. The resulting privacy loss is significant, exposing user location and potentially facilitating targeted attacks. This weakness is classified as CWE-642, Information Exposure Through Logging.
Affected Systems
The vulnerability affects Apple iOS, iPadOS, macOS (Tahoe), and visionOS. The problematic versions are iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and visionOS 26.6.1.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the moderate range, indicating a noticeable threat but not a critical one. The EPSS score indicates a very low exploitation probability (< 1%). The vulnerability is not catalogued in CISA KEV. The attack vector is inferred to be a website visited by the user; only a browser capable of loading the target page can trigger the disclosure. In practice, the risk is highest for users who rely on Private Relay for privacy protection but fail to upgrade their operating systems.
OpenCVE Enrichment