Safari 15 bug can leak your recent browsing activity and personal identifiers

A bug in Safari 15 can leak your browsing activity, and can also reveal some of the personal information attached to your Google account, according to findings from FingerprintJS, a browser fingerprinting and fraud detection service (via 9to5Mac). The vulnerability stems from an issue with Apple’s implementation of IndexedDB, an application programming interface (API) that stores data on your browser.

As explained by FingerprintJS, IndexedDB abides by the same-origin policy, which restricts one origin from interacting with data that was collected on other origins — essentially, only the website that generates data can access it. For example, if you open your email account in one tab and then open a malicious webpage in another, the same-origin policy prevents the malicious page from viewing and meddling with your email.

FingerprintJS found that Apple’s application of the IndexedDB API in Safari 15 actually violates the same-origin policy. When a website interacts with a database in Safari, FingerprintJS says that “a new (empty) database with the same name is created in all other active frames, tabs, and windows within the same browser session.”

This means other websites can see the name of other databases created on other sites, which could contain details specific to your identity. FingerprintJS notes sites that use your Google account, like YouTube, Google Calendar, and Google Keep, all generate databases with your unique Google User ID in its name. Your Google User ID allows Google to access your publicly-available information, such as your profile picture, which the Safari bug can expose to other websites.

This is a huge bug. On OSX, Safari users can (temporarily) switch to another browser to avoid their data leaking across origins. iOS users have no such choice, because Apple imposes a ban on other browser engines. https://t.co/aXdhDVIjTT

— Jake Archibald (@jaffathecake) January 16, 2022

FingerprintJS created a proof-of-concept demo you can try out if you have Safari 15 and above on your Mac, iPhone, or iPad. The demo uses the browser’s IndexedDB vulnerability to identify the sites you have open (or opened recently), and shows how sites that exploit the bug can scrape information from your Google User ID. It currently only detects 30 popular sites that are affected by the bug, such as include Instagram, Netflix, Twitter, Xbox, but it likely affects far more.

Unfortunately, there’s not much you can do to get around the issue, as FingerprintJS says the bug also affects Private Browsing mode on Safari. You can use a different browser on macOS, but Apple’s third-party browser engine ban on iOS means all browsers are affected. FingerprintJS reported the leak to the WebKit Bug Tracker on November 28th, but there hasn’t been an update to Safari yet. The Verge reached out to Apple with a request for comment but didn’t immediately hear back.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
I found Apple Vision Pro unusable at first thumbnail

I found Apple Vision Pro unusable at first

David Gewirtz/ZDNETWhen the Apple Vision Pro was first announced, a select few in the press got a chance to test it out. While many gasped at the price, a prevailing theme was the sense of magic the device conveyed through its visual interface. To choose an item, you merely glance at it. To click on
Read More
Techgigant heeft ontzettend slechte slogans thumbnail

Techgigant heeft ontzettend slechte slogans

Auteur: Onno, gepost 18 februari 2022 om 21:01 – Reageer Om de zoveel tijd komen techgiganten met nieuwe slogans en waarden. Deze techgigant ook, maar wat zijn ze slecht. We hebben bijna wel elke dag met deze techgigant te maken. Is het niet met WhatsApp dan wel met Instagram. Of Facebook. We hebben het natuurlijk…
Read More
Don't hesitate with this. New logo standard that shows the communication speed and power supply of the USB Type-C cable at a glance thumbnail

Don't hesitate with this. New logo standard that shows the communication speed and power supply of the USB Type-C cable at a glance

同じUSBケーブルでも、モノによって性能が違うわけです。USBケーブルってパッケージから空けて普通に使い始めると、どのケーブルがどの性能だったか、まずわからないし覚えてもないですよね。そんなわけで、USB技術の支援団体USBインプリメンターズ・フォーラム(USB-IF)は、USB Type-Cケーブルの給電能力を示す新しいロゴ規格を発表しました。「通信速度」と「給電能力」をロゴでわかりやすく明示できるようになり、ケーブルやポートだけでなく、パッケージにも印刷できるものとなっています。現在、最大通信速度は20Gbpsまたは40Gbps、最大給電能力は60Wまたは240Wが規定されています。USB-IFプレジデント兼最高執行責任者(COO)のジェフ・ラベンクラフト氏は、今回新しくなったロゴにより、ノートPCからスマートフォン、ディスプレイ、充電器までの消費者向け電子機器の拡大し続けるエコシステムを支えている認定USB-Cケーブルについて、USB4性能とUSBパワーデリバリー機能を消費者が容易に識別できるようになります。とコメントしています。ちなみに、今回の新しいロゴは、USB-IFの認証を受けたUSB4/USB PD 3.1ケーブルのみ利用可能で、認証を受けていないケーブルには利用できません。また今回合わせて、認定USB4ロゴもリニューアルされました。そもそもUSBケーブルの性能なんて気にしたことなんかなかった(私含む)…というそこのあなた、これを機に、今後はひと目でわかる、きちんと認証を受けて性能が良さそうなロゴ付きケーブルを使っても良いかもしれませんね。Source: BusinessWire, Jiji.com
Read More
Column: Cycling?  There's an app for that too thumbnail

Column: Cycling? There's an app for that too

Voor alles is er een app. Een bezoekje aan Rotterdam heeft mijn ogen geopend voor de potentie van fietsen via een app. Lees verder na de advertentie. Fietsen via een app Ik woon in de Achterhoek en qua nieuwe tech loopt men hier wat achter. Ik kan bijvoorbeeld geen Uber bestellen of mijn boodschappen laten…
Read More
It's not time to die - it's coming to the big screens of domestic cinemas! thumbnail

It's not time to die – it's coming to the big screens of domestic cinemas!

U četvrtak 07. oktobra u Kombank Dvorani, ali i bioskopima Cine grand i Vilin grad u Nišu s početkom u 19.30 biće prikazan najnoviji Džejms Bond- “Nije vreme za umiranje” pod rediteljskom palicom Keri Džodži Fukunaga. Ponovo nas put akcije vodi  jedinstveni   Danijel Krejg, ali i sjajna glumačka imena kao što su Rami Malek, Lea Sejdu, Lašana Linč, Ben…
Read More
Index Of News
Total
0
Share