Rechercher dans ce blog

Monday, January 17, 2022

Bug in Apple’s Safari 15 browser can leak browsing activity and personal identifiers - The Financial Express

The vulnerability stems from Apple’s implementation of IndexedDB, an application programming interface (API) that stores data on the browser.

A Safari 15 bug can leak browsing activity and also reveal personal information attached to Google accounts, according to latest findings by browser fingerprinting and fraud detection service FingerprintJS.

The vulnerability stems from Apple’s implementation of IndexedDB, an application programming interface (API) that stores data on the browser. The API follows the same-origin policy that restricts one origin from interacting with data collected on other origins — meaning, only the website that generates the data has access to it, FingerprintJS said.

However, Apple’s IndexedDB API in Safari 15 violates the same-origin policy. When a website interacts with the Safari database, a new database with the same name is created in all active tabs, frames, and windows within the same browser session, application, said FingerprintJS.

Also Read | NFT hype: 22-year-old computer science student from Indonesia becomes a millionaire selling selfies

The bug enables other websites to see the names of other databases created on other sites containing details specific to user identity. FingerprintJS noted that sites using Google accounts such as Google Keep, YouTube, and Google Calendar generate databases with a unique Google User ID in its name. This Google User ID allows Google to access the user’s public information such as profile picture, which the bug can expose to other websites.

The fraud detection service created a proof-of-concept demo for consumers using Safari 15 and above on iPhone, Mac, or iPad. The demo uses Safari’s IndexedDB vulnerability and identifies the sites the user has open and shows how sites exploiting the bug can scrape information from Google User ID. At present, it can only detect 30 popular sites affected by the bug, including Instagram, Twitter, Netflix, and Xbox.

Also Read | Amazon Great Republic Day Sale 2022 live: Big discounts on Apple iPhone 12, OnePlus 9RT, other top deals

There is little users can do to get around the issue as FingerprintJS said the bug also affected Safari’s Private Browsing mode. Mac owners can use a different browser on macOS, but Apple’s ban on third-party browser engines on iOS means all browsers would be affected. Despite FingerprintJS reporting the bug on November 28, Apple is yet to issue an update for Safari. 

Financial Express Telegram Financial Express is now on Telegram. Click here to join our channel and stay updated with the latest Biz news and updates.

Adblock test (Why?)


Bug in Apple’s Safari 15 browser can leak browsing activity and personal identifiers - The Financial Express
Read More

No comments:

Post a Comment

Nothing announces its OnePlus Nord rival ‘Phone 2a’, says it is better than Phone 1 - The Financial Express

Nothing made a bunch of announcements today. Stand-out among them was the official name drop of its next smartphone. The phone will be call...