Apple's Fraudulent Website Warning feature in Safari for iOS and Mac has come under scrutiny for using Chinese internet giant Tencent as one of its Safe Browsing providers.

The Safari feature has long sent data to Google Safe Browsing to cross-reference URLs against a blacklist and protect users against phishing scams and sites that attempt to push malware. However, it's unclear when Apple started sending user data to Tencent as well.

Apple notes in iOS that it sends some user IP addresses to Tencent, but most users are probably unaware of the fact. The mention can be found in the "About Safari & Privacy" screen, which is linked via small text under the Privacy & Security section in Settings -> Safari. The Fraudulent Website Warning feature also found here is enabled by default, so users aren't likely to know that their IP address may be logged unless they opt to view the information screen.

Apple's reference to Tencent has been found on devices running iOS 13, but some tweets suggest versions as early as iOS 12.2 also included the Chinese company as a safe browsing provider.

At this point, it's difficult to know for sure whether Apple users residing outside of China are having their data sent to Tencent, but the company appears to be mentioned on iPhones and iPads registered in the U.S. and the U.K., and possibly in other countries, too.



The privacy implications of shifting Safe Browsing to Tencent's servers are unknown, because Apple hasn't said much about it. However, according to Johns Hopkins University professor Matthew Green, a malicious provider could theoretically use Google's Safe Browsing approach to de-anonymize a user by linking their site requests.

Apple's relationship with the Chinese government has come in for increasing criticism lately, and that could make customers uneasy about Apple's links to Tencent, which is known to work closely with the Chinese Communist Party.

As such, Green believes users "deserve to be informed about this kind of change and to make choices about it. At very least, users should learn about these changes before Apple pushes the feature into production, and thus asks millions of their customers to trust them."