TechBriefly
  • Tech
  • Business
  • Science
  • Geek
  • How to
  • About
    • About Tech Briefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
  • Languages
    • 中文 (Chinese)
    • Dansk
    • Deutsch
    • Español
    • English
    • Français
    • Nederlands
    • Italiano
    • 日本语 (Japanese)
    • 한국인 (Korean)
    • Norsk
    • Polski
    • Português
    • Pусский (Russian)
    • Suomalainen
    • Svenska
No Result
View All Result
TechBriefly
No Result
View All Result
Home Tech Security

Attention Safari users: This bug can leak your browsing history and personal identifiers

As a result of a security vulnerability in Safari 15, your recent surfing activity and personal identifiers may be leaked

by Eray Eliaçık
17/01/2022
in Security, Tech
Reading Time: 2 mins read
Attention Safari users: This bug can leak your browsing history and personal identifiers
Share on FacebookShare on Twitter

According to findings from FingerprintJS, a browser fingerprinting and fraud detection service, a bug in Safari 15 may reveal your online activity and some personal information linked to your Google account (via 9to5Mac). The problem relates to Apple’s implementation of IndexedDB, an API that stores data on your browser.

IndexedDB, like all Web databases, adheres to the same-origin policy, which means that one origin can’t interact with data generated on other origins. The same-origin policy prevents a malicious page from viewing and tampering with your email if you open your email account in one tab and then visit a harmful site in another.

Attention Safari users: This bug can leak your browsing history and personal identifiers
Attention Safari users: This bug can leak your browsing history and personal identifiers

The Safari bug that exposes your Google User ID to other sites

Apple’s implementation of the IndexedDB API in Safari 15, according to FingerprintJS, violates the same-origin policy. When a website interacts with a database in Safari, FingerprintJS claims that “a new (empty) database with the same name is created in all other active frames, tabs, and windows within the same browser session.”

This indicates that other websites may view the names of other databases developed on other sites, which may contain information specific to your identity. FingerprintJS identifies websites that use your Google account, such as YouTube, Google Calendar, and Google Keep, among others. Because your Google User ID allows Google to access your publicly available data, like your profile image, the Safari vulnerability can expose it to other websites.

This is a huge bug. On OSX, Safari users can (temporarily) switch to another browser to avoid their data leaking across origins. iOS users have no such choice, because Apple imposes a ban on other browser engines. https://t.co/aXdhDVIjTT

— Jake Archibald (@jaffathecake) January 16, 2022

SEE ALSO
The Indian government warns Chrome users about a security issue

FingerprintJS created a proof-of-concept demo you may evaluate if you have Safari 15 or higher on your Mac, iPhone, or iPad. The demonstration uses the browser’s IndexedDB flaw to identify the sites you’ve got open (or recently opened), and how sites that take advantage of the flaw can gather information from your Google User ID. It currently just detects 30 major sites that are impacted by the bug, such as Instagram, Netflix, Twitter, and Xbox , but it is likely to impact far more.

Unfortunately, there isn’t much you can do about it because the bug affects Private Browsing mode in Safari as well. You may utilize a different browser on macOS, but all browsers are affected by Apple’s third-party browser engine ban on iOS. On November 28th, FingerprintJS reported the leak to the WebKit Bug Tracker, but there has yet to be an update to Safari.

Tags: APIAppleAttentionbrowserBrowsing HistorybugdangerexposefeaturedFingerprintJSgoogle accountgoogle calendarGoogle KeepGoogle User IDHowIndexedDBInstagramiOSiPadiPhoneleakmacNetflixpersonal identifiersPrivate Browsingsafarisafari 15safari bugsecurityTwittervulnerabilitywhatXboxYouTube

Related Posts

Apple mixed reality headset might be coming

Apple mixed reality headset might be coming

WhatsApp will end support for iOS 10 and iOS 11 on October 24

WhatsApp will end support for iOS 10 and iOS 11 on October 24

Google Interview Warmup will help those feeling nervous before job interviews

Google Interview Warmup will help those feeling nervous before job interviews

Apple iPhone 14 launch date might be leaked

Apple iPhone 14 launch date might be leaked

POPULAR ARTICLES

Leaked: Bel Veth LoL’s new warrior

Analysts predict a historic Apple quarter

Valve and five other companies fined millions by EU for geo-blocking

Intel brings back Glenn Hinton, a very important engineer

Bel’Veth League of Legends abilities: Gameplay explained

Plex wants to combine the contents of Netflix, Amazon, Disney and others

Dell XPS 13 Plus review

Who is Hyper NFT?

Microsoft .NET MAUI release candidate is now live

LG is considering leaving the mobile market

LATEST

How to hide your followers list on Instagram?
How to

How to hide your followers list on Instagram?

Apple mixed reality headset might be coming
AR/VR

Apple mixed reality headset might be coming

How does the upcoming Snapchat Family Center work?
How to

How does the upcoming Snapchat Family Center work?

A League of Legends slang: FF meaning in LoL
Geek

A League of Legends slang: FF meaning in LoL

WhatsApp will end support for iOS 10 and iOS 11 on October 24
Software

WhatsApp will end support for iOS 10 and iOS 11 on October 24

POPULAR GUIDES

How to hide your followers list on Instagram?

How to hide your followers list on Instagram?

How does the upcoming Snapchat Family Center work?

How does the upcoming Snapchat Family Center work?

How to send WhatsApp message without saving number?

How to send WhatsApp message without saving number?

How to use big eye filter on TikTok?

How to use big eye filter on TikTok?

How to rank on Pinterest in 2022?

How to rank on Pinterest in 2022?

TechBriefly

© 2021 TechBriefly is a Linkmedya brand.

  • About Tech Briefly
  • Privacy Policy
  • Terms and Conditions
  • Contact Us
  • Languages

Follow Us

No Result
View All Result
  • Tech
  • Business
  • Science
  • Geek
  • How to
  • About
    • About Tech Briefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
  • Languages
    • 中文 (Chinese)
    • Dansk
    • Deutsch
    • Español
    • English
    • Français
    • Nederlands
    • Italiano
    • 日本语 (Japanese)
    • 한국인 (Korean)
    • Norsk
    • Polski
    • Português
    • Pусский (Russian)
    • Suomalainen
    • Svenska