Safari History Database Tags Can Reveal What Users Were Browsing on macOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A little-known Safari database feature could give digital forensic investigators another way to understand browsing activity on macOS.

Safari’s History database can store automatically generated topic tags for some webpages, potentially revealing themes a user explored even when the original browsing records are limited.

The artifact is stored in Safari’s SQLite history database at ~/Library/Safari/History.db. This file is already a key source of browser evidence because it records visited URLs, webpage titles, timestamps, redirects, and visit counts.

Safari history data is commonly found in the history_items and history_visits tables, but two additional tables may provide useful context: history_tags and history_items_to_tags.

Safari appears to assign a short descriptive tag to some webpages it processes. Not every page receives a tag, and the precise logic used to create these labels remains unclear.

Safari History Database Tags Reveal History

According to Yogesh Khatri’s post on SwiftForensics, available evidence suggests that Safari may derive a general subject or entity related to the page rather than a precise description of its main content.

The history_tags table stores the tag metadata. Important fields include the tag title, identifier, modification timestamp, and item count.

The title field contains the human-readable tag, while the identifier field can begin with “Q,” indicating a link to a Wikidata entity. For example, a tag identifier could point to a recognized technology, organization, location, software package, or broader concept.

The history_items_to_tags table functions as a bridge between browsing records and tags. It links a history item to a tag ID, letting investigators connect Safari’s inferred topic to a specific URL.

Database triggers also update the item_count field when a tag relationship is inserted or deleted, making the count useful for identifying tags associated with multiple history items.

A SQL query can join the visit record, URL, tag title, tag identifier, and tag modification time. Since Safari timestamps use Apple’s Cocoa epoch beginning on January 1, 2001, analysts must add 978307200 seconds when converting them to Unix time.

The artifact’s value is contextual rather than conclusive. A tag may relate to an incidental concept on a page instead of its central subject.

For example, a phishing site impersonating the Homebrew project could receive an “APT” tag because Safari associates it with Advanced Package Tool, rather than because the page is linked to an advanced persistent threat.

Investigators should therefore avoid treating tags as proof of user intent. Instead, they should correlate them with URLs, visit titles, downloads, browser cache, DNS data, endpoint telemetry, and other artifacts.

Even so, older tag entries with an item_count of zero could be notable, as they may remain after associated history relationships are deleted.

The open-source macOS and iOS forensic framework mac_apt includes Safari artifact parsing and can process Safari internet history alongside other forensic evidence. Its Safari support makes the tag data easier to review during endpoint investigations.

Safari tags aren’t a standalone smoking gun, but they can help DFIR teams identify browsing patterns, investigate phishing activity, and build a clearer timeline of a macOS user’s web activity.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Safari History Database Tags Can Reveal What Users Were Browsing on macOS appeared first on Cyber Security News.