logo

Apple's 'incredibly private' Safari is not so private in Europe

ID: b5fc4ca0-b0f0-5db0-a857-be710a9c4380

STIX ID: report--b5fc4ca0-b0f0-5db0-a857-be710a9c4380

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2024-04-30

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Apple's implementation of third-party app store support in EU iOS 17.4 introduces serious privacy and security flaws in the MarketplaceKit URI scheme: any website can trigger a marketplace-kit: request that leaks a unique per-user identifier (even in private mode), MarketplaceKit fails to validate incoming JWTs and relays invalid tokens to backend endpoints, and communications lack certificate pinning—together enabling cross-site tracking, token injection, and potential MITM attacks; researchers recommend using browsers that validate origin (e.g., Brave) until Apple fixes these issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.