HeadFlash

Privacy

Apple Private Relay leak exposes real IPs; TikTok loses UK appeal

Apple investigates Private Relay IP leak; TikTok loses £12.7m child privacy appeal; Walmart sued over voiceprints; officer charged over camera misuse.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Apple investigates iCloud Private Relay flaw that exposes users’ real IP addresses

Researchers Tommy Mysk and Talal Haj Bakry discovered a series of issues in Apple’s WebKit browser engine that cause iCloud Private Relay to fail at hiding users’ real IP addresses. The flaw stems from how passkeys work: a user’s device makes a web request outside the browser itself, bypassing Private Relay’s proxied path and exposing the real IP address to the destination server. Because all browsers on iOS must use WebKit, the issues also impact OnionBrowser, an iOS app for browsing through the Tor anonymity network, though not the official Tor Browser.

Mysk said any website that supports or pretends to support passkeys can see a user’s real IP address despite Private Relay being on, and many websites have already collected this information incidentally. The researchers developed a site that lets Private Relay users check if the issues impact them, and in 404 Media’s tests, the site returned the real IP address of a supposedly protected user. OnionBrowser’s creator Mike Tigas called the issue dire, noting two of the leaks are entirely based on how iOS and WebKit work and solely in Apple’s hands. Apple told 404 Media it is investigating the report. Private Relay is part of Apple’s paid iCloud+ subscription and masks IP addresses only in Safari, unlike a true VPN that routes all device traffic.

Apple’s ‘Private Relay’ Is Exposing Users’ Real IP Addresses →

Walmart faces class action over voiceprint collection under Illinois biometric law

A group of Walmart customers filed a class action lawsuit Tuesday in Chicago under the Illinois Biometric Information Privacy Act, alleging the retail giant illegally collects their biometrics. The 15-page complaint states Walmart creates a voiceprint or biometric identifier using an AI system every time a customer calls its customer service line, without informing callers of the specific limited purposes for which the data is collected, stored, or used, beyond an automatic message mentioning business purposes including fraud prevention.

Walmart’s privacy policy, updated June 18, 2026, states the company collects biometrics such as voiceprints when customers contact them and that call recording technology is used in accordance with applicable law. The two named plaintiffs, both Illinois residents, argue the policy does not comply with state law, which requires entities to inform subjects in writing that biometric data is being collected, disclose the specific purpose and length of term, and receive a written release. The plaintiffs seek statutory damages of $1,000 to $5,000 for each violation, arguing the collection exposes consumers to serious privacy risks including identity theft and unauthorized tracking if a database is hacked. A Walmart spokesperson did not respond to a request for comment.

Walmart accused of collecting customers’ voiceprints | Courthouse News Service →

Mooresville police officer charged with using Flock cameras to track boyfriend’s ex-wife

Mooresville Police Officer Joshua Darren Sides, 37, was arrested and charged with felony accessing government computers and misdemeanor stalking after an investigation found he misused Flock Safety license-plate reading cameras. The State Bureau of Investigation found that Sides accessed the Flock Safety system 31 times between January and March 2024 to gain information about the ex-wife of a man he was dating. He was placed on administrative leave with pay pending the outcome of the case.

The investigation began after the woman reported to the Mooresville Police Department that she believed Sides was using the cameras to track her. She told investigators she had been in a relationship with Sides for about a year, that he had become obsessive and controlling, and that she ended the relationship in February 2024, after which Sides continued to contact her. Sides was arrested on August 22 and released from the Iredell County Detention Center on a $10,000 unsecured bond, with his first court appearance scheduled for September 5. The Mooresville Police Department stated Sides has been with the department since 2019.

Mooresville police officer accused of using Flock cameras to track boyfriend’s ex-wife →

TikTok lost an appeal against a £12.7m fine imposed by the UK’s Information Commissioner’s Office for illegally processing the data of over 1.4 million children under the age of 13. The Upper Tribunal ruled in favour of the ICO on Wednesday, upholding the penalty issued in April 2023 for breaches of the UK GDPR covering unlawful data processing from May 2018 to June 2020. The ICO’s investigation found TikTok had used children’s data to track and profile them and potentially present harmful or inappropriate algorithmic content without obtaining parental consent.

TikTok had argued its processing was lawful under the GDPR’s special purposes provisions, which permit processing of under-13s’ data for journalistic, academic, artistic, or literary purposes, claiming user-generated videos made with its creation tools constituted artistic expression. The court rejected that argument, stating TikTok’s claim was not sufficient and that it had no way of proving whether content was used for artistic purposes. The court said the innocent party was a commercial entity that made the operational and commercial choice not to require corroboration of users’ warranted age. ICO general counsel Binnie Goh said the decision sets an important precedent for the application of the special purposes provisions, and a TikTok spokesperson said the company is carefully considering the judgment.

TikTok loses court battle over £12.7m child privacy fine →

EFF urges Senate to reject four internet bills it says would age-gate the web

The Senate Commerce Committee will vote this week on four bills: the Kids Online Safety Act, the SCREEN Act, the Youth AI Privacy Act, and the CHATBOT Act. The Electronic Frontier Foundation opposes all four, arguing they would age-gate the internet and block young people from speaking and accessing lawful speech online. EFF states the bills are unlikely to make children and teenagers safer and would instead create sweeping new privacy and data security problems while forcing platforms to adopt unconstitutional restrictions on content for both adults and teenagers.

EFF argues the Committee should instead focus on a national consumer privacy bill protecting all internet users, or on banning behavioral advertising that tracks users across the web. The organization sent a letter to the Committee detailing its concerns about the bills.

Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction | Electronic Frontier Foundation →