AAPL · News · 20260802N
Security / bug‑reporting vulnerabilities
Apple Inc. · 2026-08-02 · Importance 28 · Surprise 42
Third‑party reporting flagged two separate security/privacy issues affecting Apple: researchers disclosed a flaw in Private Relay (WebKit/passkeys) that may expose users' IP addresses via DNS leaks, and Apple released macOS security updates to patch a critical Screen Sharing vulnerability (CVE-2026-65400). The Private Relay report warns passkey flows can bypass Private Relay and leak real IP addresses, undermining the feature's privacy guarantees. Apple’s security bulletin advises macOS Tahoe, Sequoia, and Sonoma users to update, noting the Screen Sharing flaw could allow an attacker on the same network to bypass authentication. Both items raise operational and reputational risks around privacy and may prompt regulatory scrutiny or support costs from escalated support and security hardening.
Key facts
- Apple is implementing stricter controls on bug reporting by external researchers due to an overwhelming influx of AI-generated submissions. source