Standards & regulation

Apple Can Now Edit Its Safari Block List Without An iOS Update. Publishers Should Plan For That

Hamit Tümer ·2 min read·How we report Share Print
In this piece
    One wire from far away decides what the lamp shows.
    One wire from far away decides what the lamp shows.

    The story. Apple’s iOS 27 blocks are not a one-off. WebKit now blocks programmatic data companies through a remote list that Apple devices call regularly, so entries can be added or removed without shipping a new iOS version. AdExchanger reports the list covers hundreds of companies, and Apple has not published it. (AdExchanger, Apple Has Far-Reaching Plans To Block Hundreds Of Programmatic Data Companies From iOS, 2 October 2026)

    01What happened

    • The mechanism changed. AdExchanger says WebKit’s process relies on “a remote list that Apple devices regularly call upon.” Previously a change to blocked vendors needed an iOS update.
    • It builds on this week’s blocks. Earlier, AdExchanger reported iOS 27 blocking The Trade Desk, UID2, LiveRamp, ID5, Permutive and Audigent in Safari.
    • The rules sit in WebKit. The list is applied through WebKit’s ContentRuleList, with conditions such as isRequestToKnownCrossSiteTracker. The article also cites flags for fingerprinting and tracking-prevention requests.
    • The full inventory is private. The list of potentially blocked companies is held in a private GitHub repository. AdExchanger says what is on it has not been disclosed.
    • Google is the open question. It is unclear whether ad.doubleclick.net, Google’s cookie ID pool domain, is on the list. That would leave Google as the exception.

    02What it means inside a GAM network

    Our earlier piece asked whether the block on a DSP’s serving domain was a mistake. A remote list changes that question. A blocked domain is no longer a bug waiting for the next OS release. It is a setting Apple can change on any day.

    For ad operations, that moves the risk from a release date to a calendar you cannot see. A vendor can appear on the list and drop out of Safari auctions mid-quarter, with no iOS release to point to. In a GAM network that reads as missing bids and a softer clearing price on one browser, not as an error.

    It also affects who benefits. If Google’s domain stays clear while others are blocked, the buyers and IDs left standing on Safari are fewer. That is our reading of an open question, not a reported finding.

    Apple has given itself a faster lever over programmatic data than an annual OS cycle.

    03What publishers should do about it

    04The bottom line

    Apple has given itself a faster lever over programmatic data than an annual OS cycle. Publishers cannot read the list, so the practical defence is to measure Safari closely and to avoid depending on any single ID.

    Sources & caveats

    Sources: AdExchanger, “Apple Has Far-Reaching Plans To Block Hundreds Of Programmatic Data Companies From iOS” (2 October 2026) — for the remote list, the ContentRuleList details, the private repository and the open question over ad.doubleclick.net. AdExchanger’s earlier report on iOS 27 and the Trade Desk is cited in that article for the blocked companies. The ad-operations framing and recommendations are APH desk analysis. This piece advances our 30 September coverage of the iOS 27 block.

    The weekly

    One letter a week, from the desk that runs the auctions.

    What actually moved in yield, CTV and curation across our publishers — written by the people who saw it, not a content team. No digests, no roundups, one email.

    One email a week. Unsubscribe in one click. We never share or sell the list.

    More from this issue

    Ran alongside this piece in the Weekly of 3 October 2026 —