ITP should protect against CNAME cloaking. This requires soup-specific code. See: https://webkit.org/blog/11338/cname-cloaking-and-bounce-tracking-defense/ https://trac.webkit.org/changeset/265389/webkit
We found: * The Apple code lives in NetworkDataTaskCocoa.mm * GResolver doesn't actually have support for CNAME records currently, it will need to be added