A WebKit bug report filed on September 21, 2026 by Ian Meyers of The Trade Desk traces Safari 27's refusal to load adsrvr.org, the company's ad request and delivery domain, to a hook committed to WebKit's open-source repository on February 13 and to a list of domains that Apple keeps out of that repository.
In Short
Apple's newest Safari on iPhones and iPads blocks requests to the web address The Trade Desk uses to deliver ads, because that address sits on a short, private list of domains the browser always blocks. Advertisers buying through The Trade Desk therefore cannot reach people browsing in Safari on updated devices, and several identity companies on the same list are cut off as well. The switch that makes this possible is public code from February, but the list itself belongs to Apple alone, so only Apple can take a domain off it.
A patch with no stated reason
The mechanism arrived with little ceremony. Charlie Wolfe opened WebKit bug 307853, titled "Unconditionally block requests going to certain domains", at 14:27:10 Pacific time on February 13, 2026. Its description field contains three dots and nothing else. Six seconds later the Radar WebKit Bug Importer linked the ticket to Apple's internal tracker as rdar://problem/170347008. At 14:28:19 Wolfe posted pull request 58670, and at 15:48:05 the automated EWS account recorded commit 307525@main, hash e08deedb31c1, before closing the pull request. Eighty-one minutes separated the ticket from the landed code.
The record is thin. Bug 307853 carries priority P2 and severity Normal, sits under the WebKit Misc. component against the WebKit Nightly Build, lists Wolfe as both reporter and assignee and shows a single user on its copy list. Nowhere does it say which domains the change was written for, or why.
One date discrepancy is cosmetic but worth recording. Bugzilla logs the commit on February 13 Pacific time, while GitHub's page for the pull request says the webkit-commit-queue merged it "on Feb 14". The two agree once time zones are applied: 15:48 Pacific on February 13 is 23:48 UTC, and 00:48 on February 14 in Central European Time. GitHub displays dates in the reader's local zone.
What the added lines do
GitHub's diff shows one file changed, Source/WebKit/Platform/cocoa/WebPrivacyHelpers.mm, with 11 additions and no deletions. The change comes in two halves.
A definition that is not in the repository
The first block, inserted at line 54, reads:
#if USE(APPLE_INTERNAL_SDK) && __has_include(<WebKitAdditions/WebPrivacyHelpersAdditions.mm>)
#import <WebKitAdditions/WebPrivacyHelpersAdditions.mm>
#endif
#if !defined(IS_REQUEST_UNCONDITIONALLY_BLOCKABLE)
#define IS_REQUEST_UNCONDITIONALLY_BLOCKABLE(domain) false
#endif
Two conditions govern it. When WebKit is compiled with Apple's internal software development kit and a file named WebPrivacyHelpersAdditions.mm exists in the WebKitAdditions directory, that file is imported and may supply its own definition of IS_REQUEST_UNCONDITIONALLY_BLOCKABLE. Where it does not, the macro falls back to a definition that returns false for every domain.
So what does the open-source code block? Nothing at all. Anyone compiling WebKit from the public repository gets a macro that always answers no. The list that matters exists only in Apple's builds, in a file the repository names but does not contain.
Where the check runs
The second block adds three lines inside a function named isRequestBlockable. It takes a WebCore::ResourceRequest, the engine's representation of an outgoing request, and a boolean parameter whose name the diff header cuts off at "needsAdvan". The existing code first calls TrackerDomainLookupInfo::populateIfNeeded() and derives a domain from the request's host. The new lines follow:
if (IS_REQUEST_UNCONDITIONALLY_BLOCKABLE(domain))
return true;
Placement is the point. Directly below, the pre-existing code looks the domain up in tracker data through TrackerDomainLookupInfo::find and, where the entry's canBlock() value equals TrackerDomainLookupInfo::CanBlock::No, returns false. That branch is an exemption: a domain known to Apple's tracker data but marked as not blockable. Because the unconditional check sits above it and returns early, a domain on the private list is reported as blockable before the exemption is ever consulted.
The same file soft-links a function called nw_context_set_tracker_lookup_callback from Apple's libnetwork library, behind a HAVE(SYSTEM_SUPPORT_FOR_ADVANCED_PRIVACY_PROTECTIONS) guard. The new hook therefore lives alongside the tracker lookups that feed Safari's network-level protections, not in the cookie code.
One domain, every subdomain
The value handed to the macro is not a hostname. The code builds it as a WebCore::RegistrableDomain, from a URL assembled out of the string "http://" and the request's host. A registrable domain is what browser engineers call the eTLD+1: the public suffix plus one label. Under that rule match.adsrvr.org, and every other host under adsrvr.org, collapses to adsrvr.org before the question is asked.
That detail sits at the centre of the complaint. In the ticket, Meyers wrote that the intent "seems to be to hard block domains that power 'post-cookie' identity. However, adsrvr.org is The Trade Desk's core ad request and delivery domain, not identity." He added: "The match subdomain operates on the basis of legacy third-party cookies."
His distinction is between hosts, and Apple's hook, as written, cannot draw it. The macro receives only the registrable domain, so an entry for adsrvr.org necessarily covers the match subdomain used for cookie syncing along with every host that carries bid requests and creative. Safari has blocked all third-party cookies by default since March 24, 2020, which means a subdomain that depends on them was already constrained in the browser long before this list existed. The scale of what sits behind the wall is not trivial either: Cloudflare data for the third quarter of 2025 put Safari at 15.1% of global browser traffic, against 66.3% for Chrome.
Nine entries, five companies
Apple has not published the list. The version now in circulation comes from Meyers, who wrote that the pull request "introduced unconditional blocking to Webkit/Safari, which bundled the following in Safari 27" before reproducing nine entries: tainted.example, uidapi.com, adsrvr.org, id5-sync.com, eu-1-id5-sync.com, rlcdn.com, pippio.com, permutive.com and ad.gt. The ticket does not say how he assembled it, whether from observed traffic, from inspecting the shipped browser or by some other route, and nobody from Apple has confirmed the contents in the thread.
Its existence was no secret. In July, a source-code review of the Safari 27 beta by analytics engineer Mariusz Brucki identified a category of domains hardcoded as unconditionally blockable, while noting that the contents sat in an unpublished Apple file and could not be verified from public source. The same review found that Safari's other tracking rules live in a separate system library that Apple can update without shipping a new browser. The unconditional hook differs in form, since its definition is compiled in through WebKitAdditions. Whether that definition is a fixed list, or itself calls out to data that can be updated, cannot be determined from the public diff. What Meyers' ticket adds is an itemised version on the public record.
The first entry is not a business. Names under .example are reserved for documentation and testing, which makes tainted.example look like a test fixture carried in the shipped list. The other eight belong to five companies. According to AdExchanger, which reported the story on September 29, the services added to Apple's list this month include the Unified ID 2.0 programme, which runs on uidapi.com, along with ID5, Audigent, LiveRamp and Permutive. The domain id5-sync.com is the source ID5 uses for its identifier in OpenRTB bid requests, and uidapi.com appears in those requests when ID5 distributes The Trade Desk's European identifier for a publisher. The pair rlcdn.com and pippio.com are domains associated with LiveRamp's identity products, including RampID. The last, ad.gt, is Audigent's.
The overlap with The Trade Desk's own partnerships is considerable. Its Identity Alliance combines identity providers including Experian, ID5 and LiveRamp into one cross-device layer. Experian acquired Audigent on December 4, 2024and retired the Audigent brand in August 2026, folding it into Experian Marketing Services. Three of the four other companies on the list are therefore either Identity Alliance providers or owned by one. Permutive, the fourth, works on the sell side for publishers.
The ticket, day by day
Meyers filed bug 324771, "Inclusion of adsrvr.org in IS_REQUEST_UNCONDITIONALLY_BLOCKABLE domain list", at 19:13:36 Pacific time on September 21, a week after Apple began rolling out iOS 27 on September 14. The ticket records priority P1 and severity Major, against Safari 27 on iPhone and iPad hardware running iOS 27, filed under the Page Loading component. Its only attachment, number 481466, is a 51.16 KB PNG titled "Various requests blocked on iOS27 on a yahoo.com article; non-private browsing".
That last qualifier carries weight. Domain-level network blocking arrived in Safari 17 as part of Advanced Tracking and Fingerprinting Protection, and it applied in Private Browsing. Safari 26 then made Advanced Fingerprinting Protection the default for all browsing in September 2025, though that feature restricts what classified scripts can read rather than cutting connections. The screenshot's title places these blocked requests in an ordinary session.
The exchange that followed was brief. John Wilander answered at 14:36:23 on September 22: "Thanks for filing, Ian! I also got your email. We're investigating." At 13:34:49 on September 25, Meyers asked for an ETA. Wilander replied at 13:48:34 on September 28: "I will let you know if and when any changes are available for you to test." Some five and a half hours later, at 19:14:12, the Radar importer linked the ticket to rdar://problem/188653580, seven days and 36 seconds after it was opened. In February, the same importer had linked Wolfe's ticket within six seconds. At its last modification, at 19:14 on September 28, the ticket's status remained NEW, the assignee field read Nobody and six users were copied.
According to AdExchanger, Wilander manages WebKit privacy and ad tech at Apple, and Meyers is The Trade Desk's senior director of engineering. Wilander is familiar with this terrain. In 2020 he wrote the WebKit post explaining that Safari would block all third-party cookies by default, the change that emptied the match subdomain's cookie jar in Safari six years ago.
Two details in the coverage differ from the documents. AdExchanger described the thread as sitting on GitHub; it lives on WebKit's Bugzilla, at bugs.webkit.org, while GitHub hosts the pull request the ticket cites. AdExchanger's article also spells the engineer's surname both as Meyer and as Meyers. The ticket shows Ian Meyers.
The same screenshot carries a further detail. According to AdExchanger, the ad call on yahoo.com showed The Trade Desk's bids blocked, while Google's bids, delivered through ad.doubleclick.net, went through. The ad.doubleclick.net domain does not appear among the nine entries Meyers reproduced. Neither Apple nor The Trade Desk responded to AdExchanger's requests for comment before publication, and the thread gives no reason why one buying platform's delivery domain is listed and another's is not.
What the public code cannot settle
Several questions remain open, and the diff answers none of them.
Settings
The diff shows only the lines around each insertion. Any code above line 762 that consults the truncated "needsAdvan" parameter is outside the change shown, so the patch alone does not establish whether the check depends on a user's privacy settings. Brucki's July review read the category as independent of those settings. Meyers' screenshot title describes a non-private session. Neither is a statement from Apple.
Platforms
The file sits in WebKit's Cocoa platform directory. The ticket names only iPhone and iPad under iOS 27, and nothing in it documents behaviour in Safari 27 on macOS. Nor does it address other browsers on iOS, which inherit WebKit's tracking prevention through WKWebView under App Store rules.
A fix
If Apple removes adsrvr.org, the edit happens in WebPrivacyHelpersAdditions.mm, which the public cannot see; the only outside evidence would be behaviour and whatever appears in the thread. A narrower outcome, keeping match.adsrvr.org blocked while releasing the delivery hosts, does not fit the hook as written, because the macro never receives a hostname. That would require a change at the call site in the open-source file, where it would be visible. Wilander's September 28 comment commits to notification and to nothing else.
Why buyers are watching
The timing is difficult for The Trade Desk. On August 6 it reported second-quarter revenue of $715 million, up 3%, with third-quarter guidance of at least $650 million, a figure implying a decline of roughly 12%; its shares fell 24.22% after hours to $13.39. On September 4 the company cut about 575 jobs, around 15% of its workforce, and it lost its S&P 500 seat the same day those departures took effect.
The distinction Meyers drew also matters commercially. Identity loss lowers what a demand-side platform will bid; a blocked delivery domain removes the bid. On the sell side, Permutive tied its platform to TransUnion's identity graph on September 21, the day Meyers filed his ticket. Its chief executive, Joe Root, put the addressable share of web traffic at roughly 30%, and Permutive's own August data, a vendor figure, put the penalty for carrying no identity signal at 41% lower CPMs. Those figures describe a discount. A request that never leaves the browser carries no price at all.
Safari has long been the browser where identity products were meant to earn their fees. Google said on April 22, 2025 that Chrome would keep third-party cookies, leaving Safari and Firefox as the main browsers that block them by default. OpenX and ID5 reported in December 2024 that deals carrying the ID5 ID showed a 58% increase in Safari desktop reach. The Trade Desk, for its part, gathered UID2, EUID and OpenPass under OpenTTD on March 4, 2026. The list aims at precisely that layer, and at one delivery domain beside it.
Apple's privacy controls have drawn competition scrutiny before, on the app side. France fined Apple 150 million euros in March 2025 over App Tracking Transparency, finding that Apple held third parties to stricter consent requirements than its own services. Italy's competition authority followed with a 98.6 million euro fine on December 22, 2025, and Apple has since confirmed a redesigned tracking prompt for five EU countries from iOS 27.2. Those cases concern consent for tracking inside apps, not WebKit's network rules, and neither the ticket nor AdExchanger's report mentions any regulator.
For now the public evidence consists of three documents, one screenshot and a promise of notice. The public half of the change is open for anyone to read. The list they call on remains in a file that only Apple can open.
Timeline
- March 24, 2020 - Safari begins blocking all third-party cookies by default
- September 2020 - WebKit's tracking prevention reaches every iOS browser through WKWebView
- December 4, 2024 - Experian acquires Audigent
- December 11, 2024 - OpenX and ID5 report a 58% increase in Safari desktop reach when the ID5 ID is present
- March 30, 2025 - France fines Apple 150 million euros over App Tracking Transparency
- April 22, 2025 - Google says Chrome will keep third-party cookies
- September 2025 - Safari 26 makes Advanced Fingerprinting Protection the default for all browsing
- December 22, 2025 - Italy's competition authority fines Apple 98.6 million euros over App Tracking Transparency
- February 13, 2026, 14:27 PST - Charlie Wolfe opens WebKit bug 307853, "Unconditionally block requests going to certain domains"
- February 13, 2026, 14:28 PST - Pull request 58670 is posted to the ticket
- February 13, 2026, 15:48 PST - Commit 307525@main (e08deedb31c1) lands; GitHub displays the merge as February 14
- March 4, 2026 - The Trade Desk gathers UID2, EUID and OpenPass under OpenTTD
- July 6, 2026 - A Safari 27 beta source review flags a category of unconditionally blockable domains held in an unpublished Apple file
- August 6, 2026 - The Trade Desk reports $715 million in second-quarter revenue and guides to at least $650 million for the third quarter
- August 11, 2026 - Experian retires the Audigent brand
- September 4, 2026 - The Trade Desk cuts about 575 jobs and loses its S&P 500 seat
- September 14, 2026 - Apple begins rolling out iOS 27
- September 21, 2026 - Permutive ties its platform to TransUnion's identity graph
- September 21, 2026, 19:13 PDT - Ian Meyers files WebKit bug 324771 with a screenshot of blocked requests on yahoo.com in non-private browsing
- September 22, 2026, 14:36 PDT - John Wilander replies that Apple is investigating
- September 25, 2026, 13:34 PDT - Meyers asks for an ETA
- September 28, 2026, 13:48 PDT - Wilander says he will report if and when changes are available to test
- September 28, 2026, 19:14 PDT - The ticket is linked to rdar://problem/188653580
- September 29, 2026 - AdExchanger reports that The Trade Desk cannot serve ads to Safari on iOS 27
Related PPC Land coverage
- Apple's iOS 27 blocks The Trade Desk from serving ads on Safari - The September 30 newsletter edition that first set the adsrvr.org block against the week's other platform-control stories.
- Safari 27 blocks LinkedIn and Bing ad trackers by IP address - The July source-code review that first flagged the unconditionally blockable category and its unpublished contents.
- Safari 26 tracking changes to impact marketing measurement - How Advanced Fingerprinting Protection became the default for all browsing in September 2025.
- Apple starts blocking all third-party cookies in Safari - The 2020 change, described by John Wilander in a WebKit post, that ended cookie-based matching in Safari.
- Apple introduces the Intelligent Tracking Prevention (ITP) on all browsers in iOS14 - Why every iOS browser inherits WebKit's tracking prevention.
- Trade Desk stock drops 24% as Q3 guidance points to 12% revenue decline - The August results that frame the company's position going into the Safari 27 release.
- The Trade Desk cuts about 575 jobs after growth slows to 3% - The September 4 workforce reduction.
- Trade Desk loses S&P 500 seat the same day 575 jobs end - The index removal that coincided with the layoffs.
- The Trade Desk opens its ecosystem to everyone with OpenTTD - The March 2026 portal consolidating UID2, EUID and OpenPass.
- Amazon tightens its grip as programmatic identity enters a new era - Changes to how The Trade Desk pays Identity Alliance partners including Experian, ID5 and LiveRamp.
- Experian acquires Audigent to boost data capabilities in advertising ecosystem - The December 2024 deal behind the ad.gt domain's current owner.
- OpenX and ID5 expand reach in Safari with new partnership technology - Evidence of how identity vendors priced Safari reach before the list.
- Google keeps cookies - Chrome's April 2025 decision to retain third-party cookies.
- Ad tech's most reliable numbers this week had to be pried out by courts - The weekly edition carrying Permutive's TransUnion integration and its addressability figures.
- 5 EU countries lose Apple's standard tracking prompt for a redesigned one - Apple's regulator-driven change to App Tracking Transparency from iOS 27.2.
- Apple ships Siri AI to EU Macs but not to EU iPhones - The September 14 release of iOS 27 and the rest of Apple's 2027 software.
Summary
Who: Ian Meyers of The Trade Desk filed WebKit bug 324771; John Wilander, who manages WebKit privacy and ad tech at Apple according to AdExchanger, responded; Charlie Wolfe authored the February change. The list also covers domains used by Unified ID 2.0, ID5, LiveRamp, Permutive and Audigent, now part of Experian.
What: Safari 27 blocks requests to adsrvr.org, The Trade Desk's ad request and delivery domain, because the domain sits on a list consulted through IS_REQUEST_UNCONDITIONALLY_BLOCKABLE, a macro added to WebKit in an 11-line change. The public code defaults the macro to false; Apple's builds import the real definition from an unpublished WebKitAdditions file. The check runs before WebKit's tracker exemption and operates on registrable domains, so every subdomain of a listed domain is caught.
When: The hook was committed on February 13, 2026 (February 14 on GitHub's display). iOS 27 began rolling out on September 14, 2026. Meyers filed the ticket on September 21, Wilander last replied on September 28, and AdExchanger reported the block on September 29.
Where: Safari 27 on iPhone and iPad running iOS 27, in non-private browsing according to the ticket's attachment. The code sits in WebKit's Cocoa platform directory; the ticket documents no other platform or browser.
Why: The list appears aimed at domains that supply identity after third-party cookies, according to Meyers' reading, but adsrvr.org also carries ad delivery, so its inclusion stops The Trade Desk from serving ads in Safari on updated devices. Apple has given no public explanation, and because the list is private, any change to it will be visible only through behaviour and the ticket thread.
Discussion