Explore the integration of web technologies within your app. Discuss building web-based apps, leveraging Safari functionalities, and integrating with web services.

All subtopics
Posts under Safari & Web topic

Post

Replies

Boosts

Views

Activity

Safari incorrectly shows “Fraudulent Website Warning” for a legitimate website — false positive
Hello Apple engineers and developers, I’m the owner/developer of https://mated.uz/, a legitimate SaaS platform for businesses in Uzbekistan. We have been experiencing a serious issue with Safari for approximately one month: Safari incorrectly displays a red “Fraudulent Website Warning” for our website. The important part is that the problem appears to be Safari-specific. The website works normally in: Chrome Microsoft Edge Firefox other browsers The website is a legitimate business platform and does not contain phishing pages, malware, deceptive content, or attempts to impersonate Apple or another service. What we have already done We have repeatedly submitted the domain for review through Apple’s website review process, including several requests over the past month. However, the warning is still present and we have not received a clear explanation of what is triggering the classification. We have also checked the website and its infrastructure for common causes: HTTPS / TLS certificate is valid No intentional redirects to suspicious domains No phishing or credential-harvesting pages No malware No deceptive content The website works correctly in other browsers The domain is actively used by a real operating business The problem This is becoming a real business issue because users who open our website from an iPhone or Mac using Safari may see a warning that effectively tells them our business is fraudulent. For a SaaS company, this significantly damages user trust and can prevent potential customers from accessing the platform. We would really appreciate guidance from Apple engineers on the following: How can we determine why Safari has classified our domain as fraudulent? Does Safari use an independent reputation database for this warning, separate from Google Safe Browsing? Is there any technical information or diagnostic data that website owners can use to identify the reason for the classification? Is there another escalation/review channel when the standard Website Review requests do not resolve a false positive? Are there specific DNS, hosting, redirect, TLS, domain-reputation, or third-party-script signals that we should investigate? We are happy to provide screenshots, domain information, security scan results, or any other technical information required. This appears to be a false positive affecting Safari only, and we would really appreciate any guidance on how to get the domain reviewed and the warning removed. Thank you.
0
0
314
3w
Has Meta changed its iOS in-app browser in the last few days?
We’re suddenly seeing valid Apple Wallet .pkpass files blocked inside Instagram and Messenger, with a “connection is not secure” warning. The exact same file works perfectly in Safari and outside Meta apps. We’ve reproduced it with a known-valid .pkpass hosted independently, so this doesn’t appear to be related to the pass file or hosting infrastructure. Has anyone else seen this since the latest Instagram / Messenger updates? Instagram/Messenger in-app browser → blocked Safari → works Interested to hear from anyone working with Apple Wallet / .pkpass / WKWebView.
2
0
692
3w
Unable to access logs artifact from Web Extension Packager
Hi! I've successfully uploaded my web extension using the Web Extension Packager. However, there was a build error. When I review the list of cloud builds and click "view issues" for the failed build, I get the message: "Exporting for App Store Distribution failed. Please download the logs artifact for more information." However, I can't find any link in the app store connect web UI for viewing the logs artifact for Web Extension Packager builds.
1
1
499
3w
Safari Web Extension Packager: App Store and Development export both fail, but logs artifact is missing
I’m packaging a Safari Web Extension using the web-based Safari Web Extension Packager in App Store Connect. The ZIP uploads successfully, the manifest is accepted, and the Packager automatically creates the related Extension identifier. However, every build fails during export with: Exporting for App Store Distribution failed. Please download the logs artifact for more information. It also shows: Exporting for Development Distribution failed. Please download the logs artifact for more information. There is no Logs, Artifacts, or Download button on the build or issue page. To isolate the problem, I tested: Manifest V2 and Manifest V3 A minimal extension containing only HTML and icons No JavaScript, permissions, host permissions, APIs, or external dependencies A completely new App Store Connect app A new explicit Bundle ID A name-matched extension ZIP Multiple version and build numbers Every test produced exactly the same export errors. The App Store Connect agreement is active, and the Account Holder has access to cloud-managed distribution certificates. Because even a clean minimal extension and a newly created app fail identically, this appears to happen during cloud signing, provisioning, or archive export—not while parsing the extension. Questions: How can I download the logs artifact requested by the error when the Packager interface does not provide it? Can Apple confirm whether the web-based Packager currently has an export or automatic-signing issue? Is there any required certificate, provisioning profile, App ID configuration, or account permission that the Packager does not create automatically?
0
0
32
3w
Safari Web Extension Packager: App Store and Development export both fail, but logs artifact is missing
I’m packaging a Safari Web Extension using the web-based Safari Web Extension Packager in App Store Connect. The ZIP uploads successfully, the manifest is accepted, and the Packager automatically creates the related Extension identifier. However, every build fails during export with: Exporting for App Store Distribution failed. Please download the logs artifact for more information. It also shows: Exporting for Development Distribution failed. Please download the logs artifact for more information. There is no Logs, Artifacts, or Download button on the build or issue page. To isolate the problem, I tested: Manifest V2 and Manifest V3 A minimal extension containing only HTML and icons No JavaScript, permissions, host permissions, APIs, or external dependencies A completely new App Store Connect app A new explicit Bundle ID A name-matched extension ZIP Multiple version and build numbers Every test produced exactly the same export errors. The App Store Connect agreement is active, and the Account Holder has access to cloud-managed distribution certificates. Because even a clean minimal extension and a newly created app fail identically, this appears to happen during cloud signing, provisioning, or archive export—not while parsing the extension. Questions: How can I download the logs artifact requested by the error when the Packager interface does not provide it? Can Apple confirm whether the web-based Packager currently has an export or automatic-signing issue? Is there any required certificate, provisioning profile, App ID configuration, or account permission that the Packager does not create automatically?
0
0
16
3w
Our web app trouble for CMYK image in iOS27
We tested iOS 27 Public Beta 4 and encountered an issue with our web app, which runs on smartphones. There is no problem when displaying RGB images stored in our cloud system. However, when displaying CMYK images, they sometimes fail to render entirely and appear completely white. After refreshing the screen several times, the images may appear intermittently—sometimes displaying correctly and sometimes not. What could be causing this issue? Please help us.
0
0
153
3w
Trouble with Safari Web Extension Packager
Hi! I currently have a web extension sucessfully published to Firefox. And now I'm trying to make the same web extension available for Safari. But I am having some trouble. Steps to reproduce this issue: Through appstoreconnect I create a new app. Within the app I select the tab Xcode Cloud, and scroll down to the Safari Web Extension Packager. When I try to upload a .zip file of my extension I get the error message: "NetworkError when attempting to fetch resource." According to the docs this upload feature should be compatible with any browser. I'm using Firefox version 154 running on Linux Mint 22.3. Note to forum admins: I originally tried to post this under subtopic Web Extensions but for some reason I kept getting an error when hitting "Post". That's why I'm posting this issue under the sub-topic General.
1
1
744
3w
Safari incorrectly flags sofiaproduction.ru as fraudulent — false positive
I’m the owner of sofiaproduction.ru, a legitimate videography portfolio website. Safari on iPhone continues to display a red “Fraudulent Website Warning”. The warning is reproducible on multiple iPhones and networks. The website has no login, payments, downloads, deceptive redirects, or forms requesting personal or financial information. A technical audit found no malware, phishing content, credential collection, external scripts, or TLS/DNS problems. Google Safe Browsing currently classifies the domain as clean. I have already submitted multiple requests through Apple Website Review and filed Feedback Assistant report FB24432044 with a sysdiagnose captured immediately after reproducing the warning. Apple Support confirmed that phone support cannot handle Safari website-classification issues. A separate Security Research report was closed as out of scope without being routed to the responsible team. The warning remains. Could an Apple engineer please confirm the correct escalation path or help route FB24432044 to the team responsible for Safari Fraudulent Website Warning / Safe Browsing classification? I can provide any additional technical evidence required.
Topic: Safari & Web SubTopic: General
0
0
890
4w
What is this alert ? Never happened before the betas
Hi , I have the DB 7 of Ios 27 on 17 Pro Max and Ipad Pro M5 . This alert appeared on my iPhone for the first time yesterday whilst I was reading an online article, and it reappeared this morning. On my iPad Pro, however, it doesn’t appear… I’m also running iOS 27, build 7, on my iPad Pro.
Topic: Safari & Web SubTopic: General
0
0
78
4w
Trouble with Safari Web Extension Packager
Hi! I currently have a web extension sucessfully published to Firefox. And now I'm trying to make the same web extension available for Safari. Here's a link to the source code for this extension: https://code.on.nilsnh.no/nilsnh/rolodex Steps to reproduce: Through appstoreconnect I create a new app. Within the app I select the tab Xcode Cloud, and scroll down to the Safari Web Extension Packager. When I try to upload a .zip file of my extension I get the error message: "NetworkError when attempting to fetch resource." According to the docs this upload feature should be compatible with any browser. I'm using Firefox version 154 running on Linux Mint 22.3. I've filed an issue for this last month. Support have said that they'll keep me updated but so far there's been little or no progress.
0
0
21
Aug ’26
Apple Pay JS SDK (1.latest) returns a startSession validationURL that fails merchant validation with HTTP 400
Using the official Apple Pay JS SDK (https://applepay.cdn-apple.com/jsapi/1.latest/apple-pay-sdk.js), the onvalidatemerchant event returns the validationURL: https://apple-pay-gateway.apple.com/paymentservices/startSession Our server performs merchant validation via mTLS using exactly this URL, with a valid Merchant Identity Certificate, and Apple responds with HTTP 400 Bad Request. Apple's current documentation instead references /paymentservices/paymentSession and states that "Start Session is being phased out and replaced by Payment Session". Since the URL is provided by Apple's own SDK, is startSession still valid when returned by onvalidatemerchant, and why is it rejected with 400? Anyone is experiencing this?
0
1
346
Aug ’26
Safari incorrectly shows “Fraudulent Website Warning” for a legitimate website — false positive
Hello Apple engineers and developers, I’m the owner/developer of https://mated.uz/, a legitimate SaaS platform for businesses in Uzbekistan. We have been experiencing a serious issue with Safari for approximately one month: Safari incorrectly displays a red “Fraudulent Website Warning” for our website. The important part is that the problem appears to be Safari-specific. The website works normally in: Chrome Microsoft Edge Firefox other browsers The website is a legitimate business platform and does not contain phishing pages, malware, deceptive content, or attempts to impersonate Apple or another service. What we have already done We have repeatedly submitted the domain for review through Apple’s website review process, including several requests over the past month. However, the warning is still present and we have not received a clear explanation of what is triggering the classification. We have also checked the website and its infrastructure for common causes: HTTPS / TLS certificate is valid No intentional redirects to suspicious domains No phishing or credential-harvesting pages No malware No deceptive content The website works correctly in other browsers The domain is actively used by a real operating business The problem This is becoming a real business issue because users who open our website from an iPhone or Mac using Safari may see a warning that effectively tells them our business is fraudulent. For a SaaS company, this significantly damages user trust and can prevent potential customers from accessing the platform. We would really appreciate guidance from Apple engineers on the following: How can we determine why Safari has classified our domain as fraudulent? Does Safari use an independent reputation database for this warning, separate from Google Safe Browsing? Is there any technical information or diagnostic data that website owners can use to identify the reason for the classification? Is there another escalation/review channel when the standard Website Review requests do not resolve a false positive? Are there specific DNS, hosting, redirect, TLS, domain-reputation, or third-party-script signals that we should investigate? We are happy to provide screenshots, domain information, security scan results, or any other technical information required. This appears to be a false positive affecting Safari only, and we would really appreciate any guidance on how to get the domain reviewed and the warning removed. Thank you.
Replies
0
Boosts
0
Views
314
Activity
3w
Has Meta changed its iOS in-app browser in the last few days?
We’re suddenly seeing valid Apple Wallet .pkpass files blocked inside Instagram and Messenger, with a “connection is not secure” warning. The exact same file works perfectly in Safari and outside Meta apps. We’ve reproduced it with a known-valid .pkpass hosted independently, so this doesn’t appear to be related to the pass file or hosting infrastructure. Has anyone else seen this since the latest Instagram / Messenger updates? Instagram/Messenger in-app browser → blocked Safari → works Interested to hear from anyone working with Apple Wallet / .pkpass / WKWebView.
Replies
2
Boosts
0
Views
692
Activity
3w
Unable to access logs artifact from Web Extension Packager
Hi! I've successfully uploaded my web extension using the Web Extension Packager. However, there was a build error. When I review the list of cloud builds and click "view issues" for the failed build, I get the message: "Exporting for App Store Distribution failed. Please download the logs artifact for more information." However, I can't find any link in the app store connect web UI for viewing the logs artifact for Web Extension Packager builds.
Replies
1
Boosts
1
Views
499
Activity
3w
Safari Web Extension Packager: App Store and Development export both fail, but logs artifact is missing
I’m packaging a Safari Web Extension using the web-based Safari Web Extension Packager in App Store Connect. The ZIP uploads successfully, the manifest is accepted, and the Packager automatically creates the related Extension identifier. However, every build fails during export with: Exporting for App Store Distribution failed. Please download the logs artifact for more information. It also shows: Exporting for Development Distribution failed. Please download the logs artifact for more information. There is no Logs, Artifacts, or Download button on the build or issue page. To isolate the problem, I tested: Manifest V2 and Manifest V3 A minimal extension containing only HTML and icons No JavaScript, permissions, host permissions, APIs, or external dependencies A completely new App Store Connect app A new explicit Bundle ID A name-matched extension ZIP Multiple version and build numbers Every test produced exactly the same export errors. The App Store Connect agreement is active, and the Account Holder has access to cloud-managed distribution certificates. Because even a clean minimal extension and a newly created app fail identically, this appears to happen during cloud signing, provisioning, or archive export—not while parsing the extension. Questions: How can I download the logs artifact requested by the error when the Packager interface does not provide it? Can Apple confirm whether the web-based Packager currently has an export or automatic-signing issue? Is there any required certificate, provisioning profile, App ID configuration, or account permission that the Packager does not create automatically?
Replies
0
Boosts
0
Views
32
Activity
3w
Safari Web Extension Packager: App Store and Development export both fail, but logs artifact is missing
I’m packaging a Safari Web Extension using the web-based Safari Web Extension Packager in App Store Connect. The ZIP uploads successfully, the manifest is accepted, and the Packager automatically creates the related Extension identifier. However, every build fails during export with: Exporting for App Store Distribution failed. Please download the logs artifact for more information. It also shows: Exporting for Development Distribution failed. Please download the logs artifact for more information. There is no Logs, Artifacts, or Download button on the build or issue page. To isolate the problem, I tested: Manifest V2 and Manifest V3 A minimal extension containing only HTML and icons No JavaScript, permissions, host permissions, APIs, or external dependencies A completely new App Store Connect app A new explicit Bundle ID A name-matched extension ZIP Multiple version and build numbers Every test produced exactly the same export errors. The App Store Connect agreement is active, and the Account Holder has access to cloud-managed distribution certificates. Because even a clean minimal extension and a newly created app fail identically, this appears to happen during cloud signing, provisioning, or archive export—not while parsing the extension. Questions: How can I download the logs artifact requested by the error when the Packager interface does not provide it? Can Apple confirm whether the web-based Packager currently has an export or automatic-signing issue? Is there any required certificate, provisioning profile, App ID configuration, or account permission that the Packager does not create automatically?
Replies
0
Boosts
0
Views
16
Activity
3w
Link with a quote character renders oddly
When a link contains a quote character the rendering looks off, for example https://example.com/a"b in a sentence. Is that expected behavior? Thanks.
Topic: Safari & Web SubTopic: General
Replies
0
Boosts
0
Views
69
Activity
3w
Our web app trouble for CMYK image in iOS27
We tested iOS 27 Public Beta 4 and encountered an issue with our web app, which runs on smartphones. There is no problem when displaying RGB images stored in our cloud system. However, when displaying CMYK images, they sometimes fail to render entirely and appear completely white. After refreshing the screen several times, the images may appear intermittently—sometimes displaying correctly and sometimes not. What could be causing this issue? Please help us.
Replies
0
Boosts
0
Views
153
Activity
3w
Trouble with Safari Web Extension Packager
Hi! I currently have a web extension sucessfully published to Firefox. And now I'm trying to make the same web extension available for Safari. But I am having some trouble. Steps to reproduce this issue: Through appstoreconnect I create a new app. Within the app I select the tab Xcode Cloud, and scroll down to the Safari Web Extension Packager. When I try to upload a .zip file of my extension I get the error message: "NetworkError when attempting to fetch resource." According to the docs this upload feature should be compatible with any browser. I'm using Firefox version 154 running on Linux Mint 22.3. Note to forum admins: I originally tried to post this under subtopic Web Extensions but for some reason I kept getting an error when hitting "Post". That's why I'm posting this issue under the sub-topic General.
Replies
1
Boosts
1
Views
744
Activity
3w
Safari incorrectly flags sofiaproduction.ru as fraudulent — false positive
I’m the owner of sofiaproduction.ru, a legitimate videography portfolio website. Safari on iPhone continues to display a red “Fraudulent Website Warning”. The warning is reproducible on multiple iPhones and networks. The website has no login, payments, downloads, deceptive redirects, or forms requesting personal or financial information. A technical audit found no malware, phishing content, credential collection, external scripts, or TLS/DNS problems. Google Safe Browsing currently classifies the domain as clean. I have already submitted multiple requests through Apple Website Review and filed Feedback Assistant report FB24432044 with a sysdiagnose captured immediately after reproducing the warning. Apple Support confirmed that phone support cannot handle Safari website-classification issues. A separate Security Research report was closed as out of scope without being routed to the responsible team. The warning remains. Could an Apple engineer please confirm the correct escalation path or help route FB24432044 to the team responsible for Safari Fraudulent Website Warning / Safe Browsing classification? I can provide any additional technical evidence required.
Topic: Safari & Web SubTopic: General
Replies
0
Boosts
0
Views
890
Activity
4w
What is this alert ? Never happened before the betas
Hi , I have the DB 7 of Ios 27 on 17 Pro Max and Ipad Pro M5 . This alert appeared on my iPhone for the first time yesterday whilst I was reading an online article, and it reappeared this morning. On my iPad Pro, however, it doesn’t appear… I’m also running iOS 27, build 7, on my iPad Pro.
Topic: Safari & Web SubTopic: General
Replies
0
Boosts
0
Views
78
Activity
4w
Trouble with Safari Web Extension Packager
Hi! I currently have a web extension sucessfully published to Firefox. And now I'm trying to make the same web extension available for Safari. Here's a link to the source code for this extension: https://code.on.nilsnh.no/nilsnh/rolodex Steps to reproduce: Through appstoreconnect I create a new app. Within the app I select the tab Xcode Cloud, and scroll down to the Safari Web Extension Packager. When I try to upload a .zip file of my extension I get the error message: "NetworkError when attempting to fetch resource." According to the docs this upload feature should be compatible with any browser. I'm using Firefox version 154 running on Linux Mint 22.3. I've filed an issue for this last month. Support have said that they'll keep me updated but so far there's been little or no progress.
Replies
0
Boosts
0
Views
21
Activity
Aug ’26
Apple Pay JS SDK (1.latest) returns a startSession validationURL that fails merchant validation with HTTP 400
Using the official Apple Pay JS SDK (https://applepay.cdn-apple.com/jsapi/1.latest/apple-pay-sdk.js), the onvalidatemerchant event returns the validationURL: https://apple-pay-gateway.apple.com/paymentservices/startSession Our server performs merchant validation via mTLS using exactly this URL, with a valid Merchant Identity Certificate, and Apple responds with HTTP 400 Bad Request. Apple's current documentation instead references /paymentservices/paymentSession and states that "Start Session is being phased out and replaced by Payment Session". Since the URL is provided by Apple's own SDK, is startSession still valid when returned by onvalidatemerchant, and why is it rejected with 400? Anyone is experiencing this?
Replies
0
Boosts
1
Views
346
Activity
Aug ’26