/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google says it found five separate flaws in Apple's Intelligent Tracking Prevention tool for Safari that lets users' browsing behavior be tracked

Madhumita Murgia / Financial Times :

Financial Times Madhumita Murgia

Context & Ripple Effects

When Apple introduced Intelligent Tracking Prevention in 2017, it framed the Safari feature as a shield against re-targeting even as ad groups attacked it at launch. Google's new finding flips that framing: five separate flaws mean the anti-tracking tool itself leaves browsing behavior exposed.

The disclosure also extends a pattern — Google previously went public with a "high severity" macOS kernel flaw after private reporting stalled on a patch (the 2019 kernel disclosure), so this is the second time Google has put Apple's security posture under public pressure.

First-order effects

  • Safari users get no protection from these five flaws until Apple patches them — the very tool marketed as blocking behavioral tracking is the vector for it.
  • Apple faces an awkward patch cycle: each fix must close the hole without breaking ITP's cookie-blocking behavior that it defended against ad-industry criticism in 2017.

Second-order effects

  • Google's dual role sharpens — the world's largest ad-tracking business is also the party demonstrating that Apple's privacy claims leak, giving advertisers and regulators ammunition against Apple's privacy-first positioning.
  • Recurring Safari leaks, like the later IndexedDB flaw that leaked browsing activity and Google IDs, push developers and enterprises to treat Safari's privacy features as unverified rather than trusted defaults.

Third-order effects

  • If rival-platform security research keeps exposing privacy features as attack surface, browser privacy tools will be judged by adversarial audit results, not vendor marketing — raising the cost of shipping privacy claims without external validation.
  • The pattern also feeds calls like those from researchers urging Apple and Google to open system internals to outside auditors, since closed stacks keep letting cross-platform researchers find what vendors miss.

The trend: Browser privacy features are becoming their own attack surface, with competing platforms' researchers turning each other's privacy claims into public disclosures.

Discussion

  • @lukolejnik Lukasz Olejnik on x
    Apple/Safari Intelligent Tracking Prevention is a mechanism intended to improve privacy. It was found to have privacy vulnerabilities allowing sites to track the user (and fingerprint), and to stealing web browser history of a user. Incredible find. https://arxiv.org/... https://…
  • @robinberjon Robin Berjon on x
    Legal friends: has anyone given thought about whether there's a point at which circumventing tracking protection (eg. putting the exploit below in the field) would rate as “exceeding authorized access” under the CFAA or similar? https://twitter.com/...
  • @financialtimes @financialtimes on x
    Google researchers have revealed details of multiple security flaws in Apple's Safari web browser, which were ironically found in an anti-tracking feature, that allowed users' browsing behaviour to be tracked https://www.ft.com/...
  • @salzano Corey Salzano on x
    @Techmeme @madhumita29 Google identifies flaws: 1. This exists 2. This makes Google look like crooks
  • @errorinn Erinn Atwater on x
    filing this under “we'll just tell apple to design an encryption backdoor in a safe and secure manner. they're smart and will figure it out” https://twitter.com/...
  • @ndnajnz Jeff Safire on x
    @Techmeme @madhumita29 Funny then, that Ghostery finds 30-50 trackers per day for Chrome and maybe 1 per week for Safari.
  • @patrickmcgee_ Patrick McGee on x
    “The researchers also identified a flaw that allowed hackers to “create a persistent fingerprint that will follow the user around the web"" https://twitter.com/...
  • @financialtimes @financialtimes on x
    Google has exposed details of multiple security flaws in Apple's Safari web browser that allowed users' browsing behaviour to be tracked, despite the fact that the affected tool was specifically designed to protect their privacy https://www.ft.com/...