Google Under Fire for Circumvention of Cookie Settings in Safari for iOS to Track Users

The Wall Street Journal reports that Google and several other advertising agencies have been discovered to be circumventing privacy protections in Apple's Safari browser for iOS devices in order to track users through ads on numerous popular websites. Google implemented the technique in order to embed +1 buttons on its ads, tricking users' systems into allowing cookies by using an invisible form submission to make Google's third-party cookies, which are blocked by Safari, appear as first-party cookies that are allowed.

To get around Safari's default blocking, Google exploited a loophole in the browser's privacy settings. While Safari does block most tracking, it makes an exception for websites with which a person interacts in some way—for instance, by filling out a form. So Google added coding to some of its ads that made Safari think that a person was submitting an invisible form to Google. Safari would then let Google install a cookie on the phone or computer.

The cookie that Google installed on the computer was temporary; it expired in 12 to 24 hours. But it could sometimes result in extensive tracking of Safari users. This is because of a technical quirk in Safari that allows companies to easily add more cookies to a user's computer once the company has installed at least one cookie.

google safari ios tracking
Google halted the practice once it was contacted by The Wall Street Journal about it, but has tried to downplay the impact of the issue.

In a statement, Google said: "The Journal mischaracterizes what happened and why. We used known Safari functionality to provide features that signed-in Google users had enabled. It's important to stress that these advertising cookies do not collect personal information."

In a companion blog post, The Wall Street Journal notes that the loophole that had permitted Google to bypass Safari's privacy protections has been closed in WebKit, the open source engine behind Safari, with the change having been made by two Google engineers. Consequently, Apple could and appears to be preparing to bring that fix to the public version of Safari.

An Apple spokesman said: “We are aware that some third parties are circumventing Safari’s privacy features and we are working to put a stop to it.”

An update to the software that underlies Safari has closed the loophole that allows cookies to be set after the automatic submission of invisible forms. Future public versions of Safari could incorporate that update. The people who handled the proposed change, according to software documents: two engineers at Google.

The issue was discovered by Stanford graduate student Jonathan Mayer, who has also published an extensive blog post offering additional technical details on how Google and other advertising companies circumvented Safari's default cookie settings.

Popular Stories

Touchscreen MacBook Feature

Apple Is Expected to Launch These Four MacBooks in 2026

Friday January 9, 2026 8:17 am PST by
2026 could be a bumper year for Apple's Mac lineup, with the company expected to announce as many as four separate MacBook launches. Rumors suggest Apple will court both ends of the consumer spectrum, with more affordable options for students and feature-rich premium lines for users that seek the highest specifications from a laptop. Below is a breakdown of what we're expecting over the next ...
iPhone Top Left Hole Punch Face ID Feature Purple

10 Reasons to Wait for This Year's iPhone 18 Pro

Thursday January 8, 2026 2:56 am PST by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models at the same time, which is why we often get rumored features months ahead of launch. The iPhone 18 series is no different, and we already have a good idea of what to expect for the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth...
proposed unicode emoji 18%402x

Squinting Face, Pickle, and Lighthouse Among New Emoji Coming to iOS

Friday January 9, 2026 4:24 am PST by
The Unicode Consortium has published a draft list of emoji that could come to smartphones and other devices in the future. The list shared by Emojipedia outlines 19 emoji candidates under consideration for Emoji 18.0, which is expected to be finalized in September 2026. Among the proposed additions are a squinting face emoji, left- and right-pointing thumb gestures, a pickle, a lighthouse, a ...
apple homekit ios 18 5

Apple Reminding Users of Pending Home App Upgrade Requirement

Friday January 9, 2026 10:08 am PST by
Back in late 2022 and early 2023, Apple rolled out a new architecture for its Apple Home platform to deliver improved performance and compatibility, although the rollout came with some hiccups that forced Apple to pull and later re-release the upgrade. Three years later, Apple is now on the verge of ending support for the old version of the Home architecture, which may result in access to...
grok logo purple gradient

U.S. Senators Ask Apple and Google to Remove X and Grok Apps Over Sexualized Image Generation

Friday January 9, 2026 9:43 am PST by
In a letter to Apple CEO Tim Cook and Google CEO Sundar Pichai, U.S. Senators Ron Wyden, Ben Ray Lujan, and Edward Markey have requested that Apple and Google remove X Corp's X and Grok apps from their app stores over recent incidents of "mass generation of nonconsensual sexualized images of women and children." X has come under fire over the past week amid reports of Grok's AI image...
iOS 26 Glass Feature

iOS 26 Shows Unusually Slow Adoption Months After Release

Thursday January 8, 2026 3:44 pm PST by
iOS 26 is showing unusually slow adoption among iPhone users months after release, according to third-party analytics. Usage data published by StatCounter (via Cult of Mac) for January 2026 indicates that only around 15 to 16% of active iPhones worldwide are running any version of iOS 26. The breakdown shows iOS 26.1 accounting for approximately 10.6% of devices, iOS 26.2 for about 4.6%, and ...
iphone fold text

iPhone Fold to Pave Way for Thinner, Brighter Display on iPhone Air 2

Friday January 9, 2026 3:37 am PST by
The iPhone Fold will be the first Apple device to adopt a Samsung-made OLED technology called CoE (Color Filter on Encapsulation), which could make the display brighter and thinner than previous panels, reports The Elec. In a traditional OLED panel, a polarizing film sits above the display to cut reflections and improve contrast. The drawback is that this film also absorbs some of the OLED's ...

Top Rated Comments

3N16MA Avatar
181 months ago
"Don't be evil."
Score: 36 Votes (Like | Disagree)
newagemac Avatar
181 months ago
This is completely unacceptable. You would expect this kind of behavior from some type of shady malware outfit. Is this what Google has become? I know the "don't be evil" thing was thrown out the window a long time ago but this is stooping to a new low even for Google.
Score: 32 Votes (Like | Disagree)
lifeinhd Avatar
181 months ago
It's like Google is trying to become nothing more than adware or something.

:rolleyes:
Score: 31 Votes (Like | Disagree)
jon1987 Avatar
181 months ago
If they behave in this way with someone else's browser, makes you wander what shady activities they get up to on their own.
Score: 30 Votes (Like | Disagree)
FloatingBones Avatar
181 months ago
This is evil.

This is evil. These yahoos were deliberately working around the privacy/security on a platform. There should be a massive fine and people should be fired from the company.

The really shocking thing is that very smart people within the company noted this loophole and designed the workaround. Did their ethical light-bulbs never go on? Can the government subpoena email records to see how high up the company people knew about this evil act?
Score: 30 Votes (Like | Disagree)
trainwrecka Avatar
181 months ago
Google exploits it.
Google fixes it (both on their end, and in Webkit project source)

Sounds like it really was purely unintentional. It's such a short lived behavior, they can't really get anything significant out of it.

Non-issue, only newsworthy because it's mildly interesting.

Yup, I "unintentionally" write lines of code all the time that exploit loopholes that benefit me.
Score: 29 Votes (Like | Disagree)