Google reveals security flaws in Apple’s Safari anti-tracking feature
Flaws in the Intelligent Tracking Prevention allowed Safari users to be tracked
Google researchers have discovered significant security flaws in a privacy feature in Apple’s Safari browser, which allowed for user browsing behaviour to be tracked.
In an as-yet-unpublished report seen by the Financial Times, Google researchers found that multiple flaws in Apple’s Intelligent Tracking Prevention (ITP) feature in Safari, which, somewhat ironically, enabled third parties to gain access “sensitive private information about the user’s browsing habits”.
Don't overlook your email archiving systems
Business users benefit from tools that balance productivity and compliance needsDownload now
Despite being designed to prevent users from being tracked around the web by advertisers and third-party cookies, according to Google’s report, the flaws in ITP placed Safari users’ personal data at risk, making it possible for confidential information, such as browsing behaviour, to be obtained by those who shouldn’t have access to it.
The report also claims that Google representatives informed Apple about the security flaw in August 2019.
Apple acknowledged the report in a blog post written by privacy and security engineer John Wilander in December.
“We’d like to thank Google for sending us a report in which they explore both the ability to detect when web content is treated differently by tracking prevention and the bad things that are possible with such detection,” said Wilander. “Their responsible disclosure practice allowed us to design and test the changes detailed above.”
Apple has reportedly fixed the security issues with ITP last year.
The news comes only months after Google researchers exposed a wide-ranging Apple and Android phone-hacking scheme which targeted the persecuted Uighur minority in China.
Google and Apple had previously clashed over Safari when a High Court blocked a mass lawsuit over iPhone data.
Unleashing the power of AI initiatives with the right infrastructure
What key infrastructure requirements are needed to implement AI effectively?Download now
Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey
A Veritas webinar on implementing a hybrid multi-cloud strategyDownload now
A buyer’s guide for cloud-based phone solutions
Finding the right phone system for your modern businessDownload now
The workers' experience report
How technology can spark motivation, enhance productivity and strengthen securityDownload now