Google says it found five separate flaws in Apple's Intelligent Tracking Prevention tool for Safari that lets users' browsing behavior be tracked
Madhumita Murgia / Financial Times :
Context & Ripple Effects
When Apple introduced Intelligent Tracking Prevention in 2017, it framed the Safari feature as a shield against re-targeting even as ad groups attacked it at launch. Google's new finding flips that framing: five separate flaws mean the anti-tracking tool itself leaves browsing behavior exposed.
The disclosure also extends a pattern — Google previously went public with a "high severity" macOS kernel flaw after private reporting stalled on a patch (the 2019 kernel disclosure), so this is the second time Google has put Apple's security posture under public pressure.
First-order effects
- Safari users get no protection from these five flaws until Apple patches them — the very tool marketed as blocking behavioral tracking is the vector for it.
- Apple faces an awkward patch cycle: each fix must close the hole without breaking ITP's cookie-blocking behavior that it defended against ad-industry criticism in 2017.
Second-order effects
- Google's dual role sharpens — the world's largest ad-tracking business is also the party demonstrating that Apple's privacy claims leak, giving advertisers and regulators ammunition against Apple's privacy-first positioning.
- Recurring Safari leaks, like the later IndexedDB flaw that leaked browsing activity and Google IDs, push developers and enterprises to treat Safari's privacy features as unverified rather than trusted defaults.
Third-order effects
- If rival-platform security research keeps exposing privacy features as attack surface, browser privacy tools will be judged by adversarial audit results, not vendor marketing — raising the cost of shipping privacy claims without external validation.
- The pattern also feeds calls like those from researchers urging Apple and Google to open system internals to outside auditors, since closed stacks keep letting cross-platform researchers find what vendors miss.
The trend: Browser privacy features are becoming their own attack surface, with competing platforms' researchers turning each other's privacy claims into public disclosures.