World
DNS Prefetching Can Also Leak Data Directly From the Network, Though It Requires Code

Apple has patched a security flaw in its iCloud+ "Hide My Email" feature, but researchers at software firm Mysk have discovered new vulnerabilities in another iCloud+ feature, Private Relay, that can expose users' real IP addresses. Private Relay, designed to hide a user's IP address while browsing in Safari, can be bypassed through passkeys, DNS prefetching, and WebTransport, allowing websites to see the device's actual IP address. The issue arises because passkey requests are sent directly from the operating system's authentication service, bypassing the Private Relay proxy.
DNS prefetching can also leak data directly from the network, though it requires code in a site's HTML. WebTransport, a low-latency method, can also bypass the relay. Until Apple fixes the issue, users are advised to avoid unknown websites requesting passkey access and to use a trusted system-level VPN.
Source: Donanımhaber