Apple's App Tracking Transparency Framework Isn't Foolproof, Allowing Developers to Still Track Users: Study

Researchers analysed over 1,700 iOS apps to study the effectiveness of the App Tracking Transparency framework.

Advertisement
By Jagmeet Singh | Updated: 19 April 2022 18:37 IST
Highlights
  • Apple users can choose to restrict app tracking
  • Many of the analysed apps were found to have a tracker library in place
  • Apple's privacy labels are also found to mislead users in some cases

Apple introduced its App Tracking Transparency framework in 2021

Photo Credit: Apple

Apple's App Tracking Transparency (ATT) framework, which was claimed to enhance user privacy by limiting data collection, has been found to have some weaknesses that could allow app developers to continue tracking users. An independent study has pointed out major loopholes in the framework, which Apple introduced late last year. The study also details how Privacy Nutrition Labels in the Apple App Store, which were introduced by the Cupertino company last year, might not be accurate for all apps and could be misleading in some cases.

The group of researchers, which included an independent researcher as well as four computer science experts from the University of Oxford, analysed over 1,700 iOS apps to determine the scope and effectiveness of the App Tracking Transparency framework. After its initial announcement, this privacy feature was delayed due to implementation concerns but eventually rolled out to Apple users last year. The researchers observed that while Apple's decision to force app developers to make tracking an opt-in feature made it more likely for individual users to choose to decline, it's still possible for large-scale companies to track people without them knowing.

Apple's App Tracking Transparency feature rolled out after some delay
Photo Credit: Apple

Advertisement

 

"Making the privacy properties of apps transparent through large-scale analysis remains a difficult target for independent researchers, and a key obstacle to meaningful, accountable, and verifiable privacy protections," the researchers said in the 13-page paper.

The researchers found that the ATT framework does make it harder than before for app developers to track users, since they are restricted to the limited Identifier for Advertisers (IDFA). This is one of the reasons that companies including Facebook protested Apple's move before the public release of the framework, citing disruptions to their advertising models.

Advertisement

Now, the study suggests that tracking users, even to a surprisingly granular level, is still possible to some extent. The researchers even found references to Apple itself appearing to engage in "some forms of tracking” and “invasive data practices" despite marketing privacy as a key feature of its products and services.

To understand the loopholes of the framework, the researchers analysed two versions of a total of 1,759 iOS apps from the UK App Store: one version from before iOS 14 and the other one that has been updated to comply with the updated transparency framework.

Advertisement

"Many apps still collect device information that can be used to track users at a group level (cohort tracking) or identify individuals probabilistically (fingerprinting)," the researchers noted.

The researchers also found "real-world evidence of apps computing and agreeing on a fingerprinting-derived identifier through the use of server-side code" that appears to be violating Apple's policies on privacy and data use.

Advertisement

Of the total 1,759 apps, the researchers said that 74 of them failed during the installation and instrumentation process. Analysis therefore dropped to the remaining 1,685 apps. The researchers noticed that nine of these apps were able to generate a mutual user identifier that could be used for cross-app tracking using server-side code. Those apps used an identifier generated by Alibaba subsidiary Umeng.

Some libraries, including ones from Apple and Google, were also found to be amongst the most widely used tracking tools. As much as 80 percent of the total apps incorporated at least one tracking library despite restrictions imposed by the App Store.

The new system also enabled Apple to track its users more accurately, with a larger share of advertising technologies, the research found.

In addition to the loopholes in the ATT framework, the researchers said that Privacy Nutrition Labels, which have been in place since late 2020, are not accurate in all cases and could be misleading for some apps. The labels appear on listings in the App Store to help users understand what types of data can be collected and used to track them.

Apple's Privacy Nutrition Labels could be misleading in some cases, the study suggests
Photo Credit: Apple

 

"We observed many apps that gave incomplete information or falsely declared not to collect any data at all," the researchers said.

It was also observed that while the developers of larger apps find it easier to comply with the new policies, less popular apps "may still pose an unexpected privacy risk" due to not declaring their tracking components. The researchers noted that these make up the vast majority of apps available on the App Store.

Gadgets 360 has reached out to Apple for a comment on the study and will update this article when the company responds.

This is not the first time that Apple's move to restrict app tracking has been found to have shortcomings. Shortly after the launch of the framework, a report by the Financial Times highlighted that app developer Snap had continued collecting data from users. The introduction of the framework and new privacy policies also enabled Apple to grow its advertising business and negatively affected competitors including Google, Meta, Twitter, and Snap.


Will the 2022 iPhone SE sink or swim? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Motorola Edge 70 Features Surface Online Weeks Ahead of Global Launch
  2. Vivo Launches OriginOS 6 Alongside BlueOS 3 With These New Features
  3. Oppo Reno 15 Pro Max Tipped Launch in India in 2026 At This Price
  4. Samsung Galaxy M17 5G With 50-Megapixel Camera Launched in India: See Price
  5. OnePlus Launches OxygenOS 16 Open Beta Program in India for These Models
  1. Honor Magic 8 Pro Confirmed to Get a 200-Megapixel Telephoto Camera and Advanced Image Stabilisation
  2. Slack Opens Platform for Developers to Build AI Apps and Agents on Its Data
  3. Battlefield 6 Does Not Include Content Made by Generative AI, Says EA
  4. Xiaomi 17 Ultra Camera Specifications Leaked; Could Feature 200-Megapixel Rear Camera
  5. Bybit Gains UAE’s Virtual Asset Licence; Becomes First Crypto Firm to Get Full SCA Approval
  6. Oppo Find X9 Ultra Camera Specifications Leaked; Said to Feature 200-Megapixel Rear Camera With OIS
  7. Oppo Find X9 Series With MediaTek Dimensity 9500 SoC Confirmed to Launch in India in November
  8. WhatsApp Now Lets Beta Testers Add a Link to Their Facebook Profile
  9. Fujifilm X-E5 Mirrorless Digital Camera Launched in India With X-Trans CMOS 5 HR Sensor: Price, Features
  10. Oppo Reno 15 Pro Max Launch Timeline, Price in India Leaked; Could Feature a 200-Megapixel Camera
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.