When releasing a product with GPL/LGPL source, the requirement is to provide either the source or an offer to provide the source which corresponds to the exact version of the source code used in that product "on a medium customarily used for software interchange".
So, if there were tags in the webkit repository that said "iOS-4.3.2", "iOS-4.3.3", etc. then Apple could take a tarball of it and someone requesting source could be provided with the tarball and optionally a link to the correct tag in the repository.
However, waving in the general direction of the source repository and saying "it's all in there somewhere" doesn't constitute compliance. Even if one of the Safari versions tagged in that repository happens to be the exact source that ships in some iOS 4.x, Apple has to make that relationship clear because (AFAIK) iOS is the "product" in this case, not Mobile Safari, given that the two are indivisible from the end user's perspective.
(Again IANAL, so this is all mostly based on lurking the Gpl-Violations.org list, reading their Vendor FAQ, and dealing with some reluctanctly GPL compliant companies.)