A recent iOS 27 WebKit update quietly cut off a set of programmatic data players from collecting data and serving ads on Safari and other browsers on Apple devices, and the initial small list has been replaced by a much larger, remotely managed library that can put hundreds of CDPs, ad tech and martech firms, data sellers and ID-graph operators into a probationary or actively blocked state. Firms identified earlier - The Trade Desk (Unified ID 2.0), LiveRamp, ID5, Permutive and Audigent - remain blocked on devices running iOS 27, but Apple now maintains a private GitHub-backed ContentRuleList that devices query dynamically, allowing vendors to be added or removed without an OS update and often without their knowledge. Only Apple controls which vendors are blocked, and access to the full list is restricted.
The WebKit code reveals specific criteria used to discriminate requests, including checks labeled isRequestToKnownCrossSiteTracker, !supportsFingerprintingScriptRequests and !supportsTrackingPreventionContentRuleListRequests, indicating a move toward category-wide restrictions that could encompass DMPs, DSPs and other three-letter ad-tech players. It is not confirmed whether major properties like ad.doubleclick.net are exempt. The change represents a substantive shift in how Apple enforces tracking and ad-technology access on its platform, with potentially broad consequences for programmatic advertising, identity solutions and cross-site measurement on Apple devices.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.