A vulnerability in Safari992 Archivesbe exploited to expose your browser history — and possibly elements of your identity.
Revealed in a Saturday blog post by FingerprintJS, the bug was introduced to Safari 15 via the Indexed Database API(IndexedDB), which is part of Apple's WebKitweb browser development engine. To put it simply, IndexedDB can be used to save data on your computer such as websites you've visited, making them load quicker when you return to them later.
IndexedDB also usually follows the same-origin policysecurity mechanism, which doesn't let websites freely interact with each other unless they have the same domain name (among other requirements). Think of it like being in quarantine and only being allowed to hang out with members of your household. So for example, Netflix can't access IndexedDB's saved data to find out you've been cheating on them with YouTube.
Unfortunately, the bug revealed by FingerprintJS causes IndexedDB to violate the same-origin policy, exposing data it has collected to websites it didn't collect it from. Even worse, some websites such as those in Google's network use unique user-specific identifiers in the data provided to IndexedDB. This means that, if you're logged into your Google account, the collected data can be used to precisely identify both your browsing history and details of your account. And if you're logged into more than one account, it can figure that out too.
"Not only does this imply that untrusted or malicious websites can learn a user’s identity, but it also allows the linking together of multiple separate accounts used by the same user," wrote FingerprintJS. They also released a demonstrationshowing the type of information the exploit can reveal.
FingerprintJS reported the bugat the end of last November, but Apple still hasn't fixed it. Mashable has reached out to Apple for comment.
All of this is concerning, but there isn't much you can do about it right now. Browsing in Safari's Private mode can mitigate the potential damage, since a private tab can't tell what's going on in any other tabs regardless of whether they're private or public. However it still isn't foolproof.
"[I]f you visit multiple different websites within the same [private] tab, all databases these websites interact with are leaked to all subsequently visited websites," wrote FingerprintJS.
Mac users can avoid the vulnerability by switching from Safari to a different browser, but people on iOS or iPadOS are out of luck. While only Safari has been impacted on Mac, Apple's requirement that all iOS and iPad web browsers use WebKit means the IndexedDB bug has impacted every browser on these systems. The best we can do is either wait for Apple to come out with a patch, switch to an Android, or just log off.
Topics Apple Cybersecurity
WBAI Celebrates Issue 200 by The Paris ReviewThe History of English in Ten Minutes, Dystopian Dream Books, and Other NewsReading On the Road; Fiction for a FatherGreen Car, Nightfall by Margaret WeatherfordStaff Picks: Genet’s Maids, Hockey, and Vivaldi by The Paris ReviewHappy Birthday, Gatsby; GoodA Tote for 200! by The Paris ReviewBookitecture by Sadie SteinMusic of the Heart? by Sadie SteinSmokable Songbooks, Controversial Vodka by Sadie SteinHemingway Hotels, Customized Austen, Literary Shame by Sadie SteinHorsemaning, Mars, and a Tiny Book by Sadie SteinBig Squeeze by Ezra GlinterTerry Winters by Yevgeniya TrapsThe Smell of Books; the Power of ‘Wuthering Heights’ by Sadie SteinReading in New York; Reading of London by Lorin SteinSecrets Are Lies by Bonnie NadzamStaff Picks: Biennial Cataloguing, Southern Gothic Horror by The Paris ReviewThe Rescue by John BanvilleSecrets Are Lies by Bonnie Nadzam Apple still loves you, pro users, but that love will cost you The Intercept on NSA arrest: Don't trust a thing the government tells you MLB legend Mike Schmidt apologizes after inciting Twitter outrage iOS 11 will let you beam your Wi DARPA funds researchers to give you an inside look inside AI's brains Apple sneaks 'dark mode' into iOS 11 to help save your eyes You, yes you, could play Young Dumbledore in a 'Fantastic Beasts' sequel Walmart tests a giant self Comic book that explores psychosis has no panels Facebook launches 'disaster maps' to help communities recover after crises Bobby Moynihan announces he's expecting a girl with an adorable 'Wonder Woman' post People really 'love' Facebook's Messenger reactions 'The Mummy' gets wrapped in savage reviews and buried alive Here's the full lineup of gaming events at E3 Coliseum Fan drama is getting in the way of a big 'No Man's Sky' mystery Nintendo's theme park is coming along nicely WhatsApp adds new photo sharing features and a quick reply shortcut iOS 11 isn't coming to the iPhone 5 Is Apple's HomePod a blatant ripoff of this startup's smart speaker? Apple's iOS 11 will take Facebook and Twitter down a notch
1.858s , 10131.5625 kb
Copyright © 2025 Powered by 【1992 Archives】,Miracle Information Network