Urgent.News

What's breaking now, across thousands of outlets.

Tech

AliExpress allegedly uses your browser's audio system to fingerprint your PC — hidden code runs even when no sound is playing

A developer's investigation into a Bluetooth headphone issue uncovered hidden Web Audio processing on AliExpress that allegedly fingerprints browsers and collects detailed device information.

AliExpress allegedly uses your browser's audio system to fingerprint your PC — hidden code runs even when no sound is playing

Chinese tech company Alibaba faces allegations of tracking web users through hidden audio processes on its online marketplace, AliExpress. Developer Matt Callaghan discovered the issue while troubleshooting a Bluetooth audio problem. Upon loading an AliExpress webpage in Firefox or Chrome, Callaghan noticed his phone's multipoint Bluetooth audio feature would stop playing, despite no media being played on his PC.

Closing the AliExpress tab resolved the issue immediately. Callaghan's investigation revealed two suspicious scripts, collina.js and fireyejs.js, which created a Web Audio graph using a sawtooth oscillator. The scripts measured frequency data and serialized/encrypted it before sending it to Alibaba's telemetry services using fetch() or sendBeacon() functions.

This audio fingerprinting method works even when no sound is playing, preventing multipoint Bluetooth headphones from switching between devices. Firefox and Brave have implemented protections against such fingerprinting, with Firefox adding additional safeguards in version 118 released in September 2023.

Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at tomshardware.com →

More in Tech

More from Tuesday 25 August →