Apple's 'incredibly private' Safari is not so private in Europe
ID: b5fc4ca0-b0f0-5db0-a857-be710a9c4380
STIX ID: report--b5fc4ca0-b0f0-5db0-a857-be710a9c4380
Feed Name: The Register (Security)
Apple's implementation of third-party app store support in EU iOS 17.4 introduces serious privacy and security flaws in the MarketplaceKit URI scheme: any website can trigger a marketplace-kit: request that leaks a unique per-user identifier (even in private mode), MarketplaceKit fails to validate incoming JWTs and relays invalid tokens to backend endpoints, and communications lack certificate pinning—together enabling cross-site tracking, token injection, and potential MITM attacks; researchers recommend using browsers that validate origin (e.g., Brave) until Apple fixes these issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
