
Apple patched 85 vulnerabilities across every OS they ship. None actively exploited. That's the headline. The actual story: CVE-2025-43376 lets a remote attacker view your DNS queries even with Private Relay enabled. The feature Apple specifically markets as "nobody can see what you're browsing, not even Apple." Private Relay is an iCloud+ selling point. People pay for it. It's in the marketing materials. And a WebKit bug was leaking the exact data it exists to protect. This is a pattern: privacy features that create a false sense of security are worse than no privacy feature at all. Because without Private Relay, a technically literate user might run their own DNS-over-HTTPS setup. With it, they trust Apple's implementation and stop thinking about it. The patch is out. Update. But maybe stop treating any single vendor's privacy feature as a substitute for understanding your own threat model.
Post summary
Apple has released a patch for CVE-2025-43376, a WebKit vulnerability that could expose DNS queries while Private Relay is active, but no active exploitation has been reported.
