Google reveals security flaws in Apple’s Safari anti-tracking feature

Flaws in the Intelligent Tracking Prevention allowed Safari users to be tracked

Google researchers have discovered significant security flaws in a privacy feature in Apple’s Safari browser, which allowed for user browsing behaviour to be tracked.  

In an as-yet-unpublished report seen by the Financial Times, Google researchers found that multiple flaws in Apple’s Intelligent Tracking Prevention (ITP) feature in Safari, which, somewhat ironically, enabled third parties to gain access “sensitive private information about the user’s browsing habits”.

Related Resource

Don't overlook your email archiving systems

Business users benefit from tools that balance productivity and compliance needs

Download now

Despite being designed to prevent users from being tracked around the web by advertisers and third-party cookies, according to Google’s report, the flaws in ITP placed Safari users’ personal data at risk, making it possible for confidential information, such as browsing behaviour, to be obtained by those who shouldn’t have access to it. 

The report also claims that Google representatives informed Apple about the security flaw in August 2019.

Apple acknowledged the report in a blog post written by privacy and security engineer John Wilander in December. 

“We’d like to thank Google for sending us a report in which they explore both the ability to detect when web content is treated differently by tracking prevention and the bad things that are possible with such detection,” said Wilander. “Their responsible disclosure practice allowed us to design and test the changes detailed above.” 

Apple has reportedly fixed the security issues with ITP last year.

The news comes only months after Google researchers exposed a wide-ranging Apple and Android phone-hacking scheme which targeted the persecuted Uighur minority in China.

Google and Apple had previously clashed over Safari when a High Court blocked a mass lawsuit over iPhone data.

Featured Resources

Unleashing the power of AI initiatives with the right infrastructure

What key infrastructure requirements are needed to implement AI effectively?

Download now

Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey

A Veritas webinar on implementing a hybrid multi-cloud strategy

Download now

A buyer’s guide for cloud-based phone solutions

Finding the right phone system for your modern business

Download now

The workers' experience report

How technology can spark motivation, enhance productivity and strengthen security

Download now

Most Popular

How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
WhatsApp could face €50 million GDPR fine
General Data Protection Regulation (GDPR)

WhatsApp could face €50 million GDPR fine

25 Jan 2021
How to recover deleted emails in Gmail
email delivery

How to recover deleted emails in Gmail

6 Jan 2021