Impact
The flaw resides in the state management of Apple’s Private Relay service, which allows a website to discover the device’s true IP address even when the relay is operating. This is a classic information‑disclosure weakness (CWE‑642) that compromises confidentiality by revealing a user’s network location. No other personal data is exposed, and the vulnerability does not enable code execution or privilege escalation.
Affected Systems
Apple iOS versions earlier than 18.7.10, iPadOS earlier than 18.7.10, macOS earlier than 26.6.2, and visionOS earlier than 26.6.1. These vulnerabilities are documented in Apple’s support advisories and are resolved by the corresponding updates.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity and the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious or compromised website that the user visits while Private Relay is enabled; the attacker learns the user’s real IP without obtaining further credentials.
OpenCVE Enrichment