The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.
2024-12-12T02:15:24.200
2025-11-03T22:18:29.847
Modified
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | apple | safari | < 18.2 | Yes |
| Operating System | apple | ipados | < 17.7.3 | Yes |
| Operating System | apple | ipados | < 18.2 | Yes |
| Operating System | apple | iphone_os | < 18.2 | Yes |
| Operating System | apple | macos | < 15.2 | Yes |