Explore the integration of web technologies within your app. Discuss building web-based apps, leveraging Safari functionalities, and integrating with web services.

All subtopics
Posts under Safari & Web topic

Post

Replies

Boosts

Views

Activity

iPadOS 27 (24A435): Safari crashes (SIGABRT) on first focus of a web form field after process launch
Summary On iPadOS 27.0 (build 24A435), MobileSafari crashes with SIGABRT the first time the software keyboard is brought up by focusing a form field inside a web page. It happens on any website that has a text input: we reproduced it on our own web app, amazon.co.jp, Yahoo! Mail, Gmail, Rakuten, X, and two Japanese public-sector sites. No login is required to reproduce. Environment Devices: iPad mini (A17 Pro / iPad16,2) x2, plus a third iPad (reproduced on 3 devices) OS: iPadOS 27.0 build 24A435 — both the public beta and the RC build (releaseType "User"). Also reproduces after a full erase + clean install, so it is not device-state related. NOT reproducible on: iPhone (iOS 27, same build 24A435), Chrome on the same iPads, or the Xcode 27 Simulator. Steps to reproduce (no login required) Launch Safari and open any page with a login form (e.g. the amazon.co.jp sign-in page). Without logging in, kill Safari from the app switcher (or background it and go to the Home Screen). Launch Safari again; the same page is shown. Tap any text field (ID / email / password) to focus it. Safari crashes immediately. The essential condition appears to be: the FIRST keyboard activation in a freshly launched MobileSafari process is driven by focusing a form field inside WKWebView. If the keyboard has already been built once in that process (see Workaround below), the crash never happens. Crash details We collected five .ips crash reports from three devices and two unrelated websites (our web app and amazon.co.jp). lastExceptionBacktrace is identical across all five, down to the instruction offsets, so page content is not a factor. Key frames: The exception is thrown by NSISEngine (CoreAutoLayout) while -[TUIKeyplaneView prepareForSplitTransition] removes layout constraints in an inconsistent state (this split-keyplane path is iPad-only, which explains why iPhone is unaffected). The re-entrancy: Safari's AutoFill metadata round trip (WBSAutoFillJavaScriptInjectionController -> _SFFormAutoFillController beforeStartInputSession: -> TabDocument _beginAutomaticPasswordInteraction:) calls -[UIResponder reloadInputViews] from -[WKContentView _continueElementDidFocus:requiresStrongPasswordAssistance:] while -[UIKeyboard activate] is still on the stack. In all five reports, a com.apple.root.utility-qos thread is blocked in DISPATCH_WAIT_FOR_QUEUE doing dispatch_sync onto the main queue from -[UITextChecker initGlobalsWithAsynchronousLoading:] (a once-per-process initialization). Four of the five crashes occurred 1–6 seconds after process launch. After the crash, Safari itself sometimes fails to launch until you do Settings > Safari > Clear History and Website Data. Already ruled out (all verified on device) Settings > Passwords > AutoFill turned OFF: still crashes Split keyboard setting turned OFF: still crashes Full device reset + clean install of the RC build: still crashes Site-side causes: reproduces on completely unrelated sites; the crash fires before any login/auth JavaScript runs, and no page code appears in the stack Workaround (reliable, verified) Focus Safari's own address bar FIRST, so the keyboard is constructed through a native text field without the asynchronous AutoFill round trip. After that, focusing web form fields works normally for the lifetime of the process. This workaround is unavailable in SFSafariViewController / in-app browsers, where the crash also reproduces. Questions Can anyone else reproduce this on iPadOS 27.0 (24A435)? Confirmations/boosts appreciated — we want to know how widespread this is before the public rollout. Is there any site-side mitigation (markup, autocomplete attributes, JS) that prevents Safari's AutoFill round trip from re-entering keyboard construction? Standard autocomplete attributes did not help in our tests. Is this a known regression being tracked for an iPadOS 27.x update? Is there any mitigation for SFSafariViewController-based in-app browsers, where the address-bar workaround cannot be used? Filed via Feedback Assistant: FBxxxxxxxx (five .ips crash reports attached there).
Topic: Safari & Web SubTopic: General
1
1
875
6h
Safari flags my café website as deceptive - no response to review request
Hi, Safari shows a “Deceptive Website” warning for https://mim-kulinariya.com/. It’s a simple café menu with prices and contact details. No login, payments, personal data collection forms or tracking scripts. It’s hosted on GitHub Pages with a valid Let’s Encrypt certificate. I submitted a review request through websitereview.apple.com but have received no response at all. The warning discourages customers from visiting our website. Could someone from Apple please help expedite the review or explain how to escalate this? If a specific page or resource triggered the warning, please let us know so we can address it promptly. Thank you.
Topic: Safari & Web SubTopic: General
0
0
38
10h
Unable to access logs artifact from Web Extension Packager
Hi! I've successfully uploaded my web extension using the Web Extension Packager. However, there was a build error. When I review the list of cloud builds and click "view issues" for the failed build, I get the message: "Exporting for App Store Distribution failed. Please download the logs artifact for more information." However, I can't find any link in the app store connect web UI for viewing the logs artifact for Web Extension Packager builds.
2
2
806
1d
Video's to display in Safari
Hi everyone, I am new to this forum, and I have a question about Safari not displaying my .mp4 videos on my corporate website. This is probably an issue that has been posted before, but any help is welcome. I manage a major Travel portal, and I don't want to disappoint about 30% of my traffic coming in via Safari. Thanks in advance for any help or advice, -Paul
Topic: Safari & Web SubTopic: General
1
0
1k
1d
Safari shows “Fraudulent Website Warning” for q-saver.com for over 5 months despite repeated Website Review requests
Safari displays a red “Fraudulent Website Warning” for my website q-saver.com. The warning has been present for more than 5 months. I have already submitted two requests through https://websitereview.apple.com/, but neither resulted in the warning being removed or any response. The website is a video downloading service. It does not impersonate Apple or financial services and does not ask for Apple IDs, banking credentials or other sensitive information. The only password it asks for is the optional password of a q-saver.com account; sign-in with Google or Telegram goes through their official OAuth pages, and payments are processed on the payment providers' own pages. The site used to show pop-under ads from third-party ad networks. They have been turned off (the last one on September 26, 2026), and the ad network code has been removed from the pages. On 27 September I submitted a new Website Review request. Google Safe Browsing reports no unsafe content for the site: https://transparencyreport.google.com/safe-browsing/search?url=q-saver.com The website works normally in Chrome, Firefox and Edge. In iOS in-app browsers (for example, Telegram) it does not open at all because of the warning. Is there an official escalation path for Safari's Fraudulent Website Warning classification when Website Review requests remain unresolved for several months? I can provide screenshots and technical information privately if required.
0
0
458
2d
Website incorrectly blocked by Apple's adult content filter
Hi everyone, I'm hoping someone can help with an issue I'm having with Apple's Web Content Restrictions. I manage a legitimate fitness and wellness website, but some iPhone/iPad users are unable to access it when they have: Settings → Screen Time → Content & Privacy Restrictions → App Store, Media, Web & Games → Web Content → Limit Adult Websites enabled. They receive: Website Not Allowed The website is a restricted website. I've been able to reproduce the exact same issue myself by enabling this setting on an iPhone. The important point is that the website is not adult content whatsoever. It is a normal fitness/wellness website providing workouts, fitness programmes, nutrition guidance and related content. There is no pornography, sexually explicit content or adult services. I've also tested blank pages and different URLs associated with the site, and the restriction still occurs. Everything works normally when the Web Content setting is changed to Unrestricted Access. I've contacted Apple Support and Apple Developer Support but haven't been able to get the issue in front of someone who can review the website's classification. Does anyone know how to request a review or reclassification of a website that appears to have been incorrectly flagged by Apple's Web Content Filter? I'm not trying to bypass Apple's parental controls. I simply want to understand how a legitimate fitness website can be reviewed and removed from whatever classification is causing it to be blocked under Limit Adult Websites. Any advice from anyone who has dealt with this before would be hugely appreciated.
Topic: Safari & Web SubTopic: General
0
1
226
4d
WebAuthn Conditional UI / Passkeys: Is zero-click biometric authentication (Face ID) on Safari web apps planned or possible?
Hello I am developing a web application using Next.js and attempting to implement Passkeys / WebAuthn for session unlocking on iOS Safari. My specific requirement is to achieve a seamless, zero-click biometric unlock experience (Face ID) for returning users upon page load or refresh, similar to native app behavior, without requiring any physical user interaction (such as tapping the keyboard suggestion in Conditional UI or tapping a system modal like ⁠ASAuthorizationController⁠). Could you please clarify: Does the WebKit / Safari architecture strictly prohibit silent, programmatic invocation of ⁠navigator.credentials.get()⁠ with ⁠mediation: 'conditional'⁠ or any other configuration without a direct, user-initiated gesture or touch event? Is there any existing or upcoming API in Safari/iOS that allows web apps to trigger Face ID verification automatically upon page load, or is user presence (tap/interaction) a permanent, hard requirement enforced by iOS security for web browsers?
Topic: Safari & Web SubTopic: General
0
0
234
5d
Web Push returns HTTP 200, but no push event is received by PWA on iPad
I am implementing push notifications using Web Push for a web application running as a PWA on iPad. When sending a push notification to the web application, the push service returns an HTTP 200 response. However, no notification is displayed on the PWA, and the Service Worker's push event is not triggered. If I create a new push subscription and send the notification using the newly issued endpoint, notifications start working again. Notifications are not disabled in the iPad notification settings, so I would like to understand what could cause this situation. I am using a commonly used JavaScript Web Push library to send the push notifications. I would also like to know whether there is any way to detect or confirm that a push subscription is in this state, other than observing that notifications are no longer being delivered. In particular, if the push service returns HTTP 200 but the notification is not delivered and the Service Worker's push event is not triggered, is there any way for the application server or the PWA to determine that the existing push subscription is no longer usable and needs to be renewed?
0
0
228
5d
Safari Web Extension Packager missing from Xcode Cloud tab in App Store Connect
Hello, I am trying to package and distribute a Safari Web Extension using the web-based Safari Web Extension Packager in App Store Connect. My Apple Developer Program membership is active, and I have already completed the following: Created an explicit Bundle ID. Created an iOS app record in App Store Connect named Kuzey SGK. The app is currently in Prepare for Submission status. I can access the app's Xcode Cloud tab. I can also access Users and Access > Xcode Cloud. According to Apple's documentation: “After creating an app record, navigate to the Xcode Cloud tab. Under Safari Web Extension Packager, click Upload.” However, there is no “Safari Web Extension Packager” section at all under the Xcode Cloud tab for my app. The page only displays the standard Xcode Cloud information and “Get started in Xcode.” I am using App Store Connect from Windows in a web browser. My understanding from Apple's Safari Web Extension documentation is that the web-based packager should allow packaging an existing web extension without requiring a Mac or Xcode. I have not configured a standard Xcode Cloud workflow or connected a source repository, because the Safari Web Extension Packager documentation does not list those steps as prerequisites. Apple Developer Program Support reviewed my request and referred me to the Developer Forums because this appears to be a technical issue. My support case number is 102956602442. Could someone please clarify: Is there an additional step required to enable the Safari Web Extension Packager for a newly created developer account or app? Is a standard Xcode Cloud workflow required before the Packager becomes visible? Is the Packager currently available to all Apple Developer Program members? Thank you.
1
0
371
6d
iPadOS 27 (24A435): Safari crashes (SIGABRT) on first focus of a web form field after process launch
Summary On iPadOS 27.0 (build 24A435), MobileSafari crashes with SIGABRT the first time the software keyboard is brought up by focusing a form field inside a web page. It happens on any website that has a text input: we reproduced it on our own web app, amazon.co.jp, Yahoo! Mail, Gmail, Rakuten, X, and two Japanese public-sector sites. No login is required to reproduce. Environment Devices: iPad mini (A17 Pro / iPad16,2) x2, plus a third iPad (reproduced on 3 devices) OS: iPadOS 27.0 build 24A435 — both the public beta and the RC build (releaseType "User"). Also reproduces after a full erase + clean install, so it is not device-state related. NOT reproducible on: iPhone (iOS 27, same build 24A435), Chrome on the same iPads, or the Xcode 27 Simulator. Steps to reproduce (no login required) Launch Safari and open any page with a login form (e.g. the amazon.co.jp sign-in page). Without logging in, kill Safari from the app switcher (or background it and go to the Home Screen). Launch Safari again; the same page is shown. Tap any text field (ID / email / password) to focus it. Safari crashes immediately. The essential condition appears to be: the FIRST keyboard activation in a freshly launched MobileSafari process is driven by focusing a form field inside WKWebView. If the keyboard has already been built once in that process (see Workaround below), the crash never happens. Crash details We collected five .ips crash reports from three devices and two unrelated websites (our web app and amazon.co.jp). lastExceptionBacktrace is identical across all five, down to the instruction offsets, so page content is not a factor. Key frames: The exception is thrown by NSISEngine (CoreAutoLayout) while -[TUIKeyplaneView prepareForSplitTransition] removes layout constraints in an inconsistent state (this split-keyplane path is iPad-only, which explains why iPhone is unaffected). The re-entrancy: Safari's AutoFill metadata round trip (WBSAutoFillJavaScriptInjectionController -> _SFFormAutoFillController beforeStartInputSession: -> TabDocument _beginAutomaticPasswordInteraction:) calls -[UIResponder reloadInputViews] from -[WKContentView _continueElementDidFocus:requiresStrongPasswordAssistance:] while -[UIKeyboard activate] is still on the stack. In all five reports, a com.apple.root.utility-qos thread is blocked in DISPATCH_WAIT_FOR_QUEUE doing dispatch_sync onto the main queue from -[UITextChecker initGlobalsWithAsynchronousLoading:] (a once-per-process initialization). Four of the five crashes occurred 1–6 seconds after process launch. After the crash, Safari itself sometimes fails to launch until you do Settings > Safari > Clear History and Website Data. Already ruled out (all verified on device) Settings > Passwords > AutoFill turned OFF: still crashes Split keyboard setting turned OFF: still crashes Full device reset + clean install of the RC build: still crashes Site-side causes: reproduces on completely unrelated sites; the crash fires before any login/auth JavaScript runs, and no page code appears in the stack Workaround (reliable, verified) Focus Safari's own address bar FIRST, so the keyboard is constructed through a native text field without the asynchronous AutoFill round trip. After that, focusing web form fields works normally for the lifetime of the process. This workaround is unavailable in SFSafariViewController / in-app browsers, where the crash also reproduces. Questions Can anyone else reproduce this on iPadOS 27.0 (24A435)? Confirmations/boosts appreciated — we want to know how widespread this is before the public rollout. Is there any site-side mitigation (markup, autocomplete attributes, JS) that prevents Safari's AutoFill round trip from re-entering keyboard construction? Standard autocomplete attributes did not help in our tests. Is this a known regression being tracked for an iPadOS 27.x update? Is there any mitigation for SFSafariViewController-based in-app browsers, where the address-bar workaround cannot be used? Filed via Feedback Assistant: FBxxxxxxxx (five .ips crash reports attached there).
Topic: Safari & Web SubTopic: General
Replies
1
Boosts
1
Views
875
Activity
6h
Safari flags my café website as deceptive - no response to review request
Hi, Safari shows a “Deceptive Website” warning for https://mim-kulinariya.com/. It’s a simple café menu with prices and contact details. No login, payments, personal data collection forms or tracking scripts. It’s hosted on GitHub Pages with a valid Let’s Encrypt certificate. I submitted a review request through websitereview.apple.com but have received no response at all. The warning discourages customers from visiting our website. Could someone from Apple please help expedite the review or explain how to escalate this? If a specific page or resource triggered the warning, please let us know so we can address it promptly. Thank you.
Topic: Safari & Web SubTopic: General
Replies
0
Boosts
0
Views
38
Activity
10h
Unable to access logs artifact from Web Extension Packager
Hi! I've successfully uploaded my web extension using the Web Extension Packager. However, there was a build error. When I review the list of cloud builds and click "view issues" for the failed build, I get the message: "Exporting for App Store Distribution failed. Please download the logs artifact for more information." However, I can't find any link in the app store connect web UI for viewing the logs artifact for Web Extension Packager builds.
Replies
2
Boosts
2
Views
806
Activity
1d
Video's to display in Safari
Hi everyone, I am new to this forum, and I have a question about Safari not displaying my .mp4 videos on my corporate website. This is probably an issue that has been posted before, but any help is welcome. I manage a major Travel portal, and I don't want to disappoint about 30% of my traffic coming in via Safari. Thanks in advance for any help or advice, -Paul
Topic: Safari & Web SubTopic: General
Replies
1
Boosts
0
Views
1k
Activity
1d
Safari shows “Fraudulent Website Warning” for q-saver.com for over 5 months despite repeated Website Review requests
Safari displays a red “Fraudulent Website Warning” for my website q-saver.com. The warning has been present for more than 5 months. I have already submitted two requests through https://websitereview.apple.com/, but neither resulted in the warning being removed or any response. The website is a video downloading service. It does not impersonate Apple or financial services and does not ask for Apple IDs, banking credentials or other sensitive information. The only password it asks for is the optional password of a q-saver.com account; sign-in with Google or Telegram goes through their official OAuth pages, and payments are processed on the payment providers' own pages. The site used to show pop-under ads from third-party ad networks. They have been turned off (the last one on September 26, 2026), and the ad network code has been removed from the pages. On 27 September I submitted a new Website Review request. Google Safe Browsing reports no unsafe content for the site: https://transparencyreport.google.com/safe-browsing/search?url=q-saver.com The website works normally in Chrome, Firefox and Edge. In iOS in-app browsers (for example, Telegram) it does not open at all because of the warning. Is there an official escalation path for Safari's Fraudulent Website Warning classification when Website Review requests remain unresolved for several months? I can provide screenshots and technical information privately if required.
Replies
0
Boosts
0
Views
458
Activity
2d
Website incorrectly blocked by Apple's adult content filter
Hi everyone, I'm hoping someone can help with an issue I'm having with Apple's Web Content Restrictions. I manage a legitimate fitness and wellness website, but some iPhone/iPad users are unable to access it when they have: Settings → Screen Time → Content & Privacy Restrictions → App Store, Media, Web & Games → Web Content → Limit Adult Websites enabled. They receive: Website Not Allowed The website is a restricted website. I've been able to reproduce the exact same issue myself by enabling this setting on an iPhone. The important point is that the website is not adult content whatsoever. It is a normal fitness/wellness website providing workouts, fitness programmes, nutrition guidance and related content. There is no pornography, sexually explicit content or adult services. I've also tested blank pages and different URLs associated with the site, and the restriction still occurs. Everything works normally when the Web Content setting is changed to Unrestricted Access. I've contacted Apple Support and Apple Developer Support but haven't been able to get the issue in front of someone who can review the website's classification. Does anyone know how to request a review or reclassification of a website that appears to have been incorrectly flagged by Apple's Web Content Filter? I'm not trying to bypass Apple's parental controls. I simply want to understand how a legitimate fitness website can be reviewed and removed from whatever classification is causing it to be blocked under Limit Adult Websites. Any advice from anyone who has dealt with this before would be hugely appreciated.
Topic: Safari & Web SubTopic: General
Replies
0
Boosts
1
Views
226
Activity
4d
WebAuthn Conditional UI / Passkeys: Is zero-click biometric authentication (Face ID) on Safari web apps planned or possible?
Hello I am developing a web application using Next.js and attempting to implement Passkeys / WebAuthn for session unlocking on iOS Safari. My specific requirement is to achieve a seamless, zero-click biometric unlock experience (Face ID) for returning users upon page load or refresh, similar to native app behavior, without requiring any physical user interaction (such as tapping the keyboard suggestion in Conditional UI or tapping a system modal like ⁠ASAuthorizationController⁠). Could you please clarify: Does the WebKit / Safari architecture strictly prohibit silent, programmatic invocation of ⁠navigator.credentials.get()⁠ with ⁠mediation: 'conditional'⁠ or any other configuration without a direct, user-initiated gesture or touch event? Is there any existing or upcoming API in Safari/iOS that allows web apps to trigger Face ID verification automatically upon page load, or is user presence (tap/interaction) a permanent, hard requirement enforced by iOS security for web browsers?
Topic: Safari & Web SubTopic: General
Replies
0
Boosts
0
Views
234
Activity
5d
Web Push returns HTTP 200, but no push event is received by PWA on iPad
I am implementing push notifications using Web Push for a web application running as a PWA on iPad. When sending a push notification to the web application, the push service returns an HTTP 200 response. However, no notification is displayed on the PWA, and the Service Worker's push event is not triggered. If I create a new push subscription and send the notification using the newly issued endpoint, notifications start working again. Notifications are not disabled in the iPad notification settings, so I would like to understand what could cause this situation. I am using a commonly used JavaScript Web Push library to send the push notifications. I would also like to know whether there is any way to detect or confirm that a push subscription is in this state, other than observing that notifications are no longer being delivered. In particular, if the push service returns HTTP 200 but the notification is not delivered and the Service Worker's push event is not triggered, is there any way for the application server or the PWA to determine that the existing push subscription is no longer usable and needs to be renewed?
Replies
0
Boosts
0
Views
228
Activity
5d
Safari Web Extension Packager missing from Xcode Cloud tab in App Store Connect
Hello, I am trying to package and distribute a Safari Web Extension using the web-based Safari Web Extension Packager in App Store Connect. My Apple Developer Program membership is active, and I have already completed the following: Created an explicit Bundle ID. Created an iOS app record in App Store Connect named Kuzey SGK. The app is currently in Prepare for Submission status. I can access the app's Xcode Cloud tab. I can also access Users and Access > Xcode Cloud. According to Apple's documentation: “After creating an app record, navigate to the Xcode Cloud tab. Under Safari Web Extension Packager, click Upload.” However, there is no “Safari Web Extension Packager” section at all under the Xcode Cloud tab for my app. The page only displays the standard Xcode Cloud information and “Get started in Xcode.” I am using App Store Connect from Windows in a web browser. My understanding from Apple's Safari Web Extension documentation is that the web-based packager should allow packaging an existing web extension without requiring a Mac or Xcode. I have not configured a standard Xcode Cloud workflow or connected a source repository, because the Safari Web Extension Packager documentation does not list those steps as prerequisites. Apple Developer Program Support reviewed my request and referred me to the Developer Forums because this appears to be a technical issue. My support case number is 102956602442. Could someone please clarify: Is there an additional step required to enable the Safari Web Extension Packager for a newly created developer account or app? Is a standard Xcode Cloud workflow required before the Packager becomes visible? Is the Packager currently available to all Apple Developer Program members? Thank you.
Replies
1
Boosts
0
Views
371
Activity
6d