Google reveals security flaws in Apple’s Safari anti-tracking feature

Flaws in the Intelligent Tracking Prevention allowed Safari users to be tracked

Google researchers have discovered significant security flaws in a privacy feature in Apple’s Safari browser, which allowed for user browsing behaviour to be tracked.  

In an as-yet-unpublished report seen by the Financial Times, Google researchers found that multiple flaws in Apple’s Intelligent Tracking Prevention (ITP) feature in Safari, which, somewhat ironically, enabled third parties to gain access “sensitive private information about the user’s browsing habits”.

Related Resource

Don't overlook your email archiving systems

Business users benefit from tools that balance productivity and compliance needs

Download now

Despite being designed to prevent users from being tracked around the web by advertisers and third-party cookies, according to Google’s report, the flaws in ITP placed Safari users’ personal data at risk, making it possible for confidential information, such as browsing behaviour, to be obtained by those who shouldn’t have access to it. 

The report also claims that Google representatives informed Apple about the security flaw in August 2019.

Apple acknowledged the report in a blog post written by privacy and security engineer John Wilander in December. 

“We’d like to thank Google for sending us a report in which they explore both the ability to detect when web content is treated differently by tracking prevention and the bad things that are possible with such detection,” said Wilander. “Their responsible disclosure practice allowed us to design and test the changes detailed above.” 

Apple has reportedly fixed the security issues with ITP last year.

The news comes only months after Google researchers exposed a wide-ranging Apple and Android phone-hacking scheme which targeted the persecuted Uighur minority in China.

Google and Apple had previously clashed over Safari when a High Court blocked a mass lawsuit over iPhone data.

Featured Resources

Unlocking collaboration: Making software work better together

How to improve collaboration and agility with the right tech

Download now

Four steps to field service excellence

How to thrive in the experience economy

Download now

Six things a developer should know about Postgres

Why enterprises are choosing PostgreSQL

Download now

The path to CX excellence for B2B services

The four stages to thrive in the experience economy

Download now

Most Popular

Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

8 Apr 2021
Hackers are using fake messages to break into WhatsApp accounts
instant messaging (IM)

Hackers are using fake messages to break into WhatsApp accounts

8 Apr 2021