• About Us
  • Contact Us
  • Cookie policy (EU)
  • Home
  • Privacy Policy
  • Video
  • Write for us
Today Headline
  • HOME
  • NEWS
    • POLITICS
    • News for today
    • Borisov news
  • FINANCE
    • Business
    • Insurance
  • Video
  • TECHNOLOGY
  • ENTERPRISE
  • LIFESTYLE
    • TRAVEL
    • HEALTH
    • ENTERTAINMENT
  • AUTOMOTIVE
  • SPORTS
  • Travel and Tourism
  • HOME
  • NEWS
    • POLITICS
    • News for today
    • Borisov news
  • FINANCE
    • Business
    • Insurance
  • Video
  • TECHNOLOGY
  • ENTERPRISE
  • LIFESTYLE
    • TRAVEL
    • HEALTH
    • ENTERTAINMENT
  • AUTOMOTIVE
  • SPORTS
  • Travel and Tourism
No Result
View All Result
TodayHeadline
No Result
View All Result

Safari 15 bug can leak your recent browsing activity and personal identifiers – The Verge

January 16, 2022
in News
0
Safari 15 bug can leak your recent browsing activity and personal identifiers – The Verge
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter

A bug in Safari 15 can leak your browsing activity, and can also reveal some of the personal information attached to your Google account, according to findings from FingerprintJS, a browser fingerprinting and fraud detection service (via 9to5Mac). The vulnerability stems from an issue with Apple’s implementation of IndexedDB, an application programming interface (API) that stores data on your browser.

As explained by FingerprintJS, IndexedDB abides by the same-origin policy, which restricts one origin from interacting with data that was collected on other origins — essentially, only the website that generates data can access it. For example, if you open your email account in one tab and then open a malicious webpage in another, the same-origin policy prevents the malicious page from viewing and meddling with your email.

There’s not much you can do to get around the issue

FingerprintJS found that Apple’s application of the IndexedDB API in Safari 15 actually violates the same-origin policy. When a website interacts with a database in Safari, FingerprintJS says that “a new (empty) database with the same name is created in all other active frames, tabs, and windows within the same browser session.”

This means other websites can see the name of other databases created on other sites, which could contain details specific to your identity. FingerprintJS notes sites that use your Google account, like YouTube, Google Calendar, and Google Keep, all generate databases with your unique Google User ID in its name. Your Google User ID allows Google to access your publicly-available information, such as your profile picture, which the Safari bug can expose to other websites.

This is a huge bug. On OSX, Safari users can (temporarily) switch to another browser to avoid their data leaking across origins. iOS users have no such choice, because Apple imposes a ban on other browser engines. https://t.co/aXdhDVIjTT

— Jake Archibald (@jaffathecake) January 16, 2022

FingerprintJS created a proof-of-concept demo you can try out if you have Safari 15 and above on your Mac, iPhone, or iPad. The demo uses the browser’s IndexedDB vulnerability to identify the sites you have open (or opened recently), and shows how sites that exploit the bug can scrape information from your Google User ID. It currently only detects 30 popular sites that are affected by the bug, such as include Instagram, Netflix, Twitter, Xbox, but it likely affects far more.

Unfortunately, there’s not much you can do to get around the issue, as FingerprintJS says the bug also affects Private Browsing mode on Safari. You can use a different browser on macOS, but Apple’s third-party browser engine ban on iOS means all browsers are affected. FingerprintJS reported the leak to the WebKit Bug Tracker on November 28th, but there hasn’t been an update to Safari yet. The Verge reached out to Apple with a request for comment but didn’t immediately hear back.

Previous Post

Scream 5 finally unseats Spider-Man: No Way Home at the North American box-office – Fox Business

Next Post

Tonga volcano eruption: What we know so far – Al Jazeera English

Related Posts

Shares recover even as growth, inflation fears linger – Reuters.com
News

Shares recover even as growth, inflation fears linger – Reuters.com

https://www.reuters.com/markets/europe/global-markets-wrapup-1-2022-05-17/

Read more
Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN
News

Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN

https://www.cnn.com/2022/05/17/us/buffalo-supermarket-shooting-tuesday/index.html

Read more
PGA Championship 2022: Updated Odds & Picks for Jordan Spieth, Rory McIlroy, More – The Action Network
News

PGA Championship 2022: Updated Odds & Picks for Jordan Spieth, Rory McIlroy, More – The Action Network

https://www.actionnetwork.com/golf/2022-pga-championship-odds-picks-predictions-jordan-spieth-sobel

Read more
PGA Championship 2022: Updated Odds & Picks for Jordan Spieth, Rory McIlroy, More – The Action Network
News

PGA Championship 2022: Updated Odds & Picks for Jordan Spieth, Rory McIlroy, More – The Action Network

https://www.actionnetwork.com/golf/2022-pga-championship-odds-picks-predictions-jordan-spieth-sobel

Read more
Judge temporarily delays execution of man who killed 8-year-old, raped 10-year-old – Yahoo News
News

Judge temporarily delays execution of man who killed 8-year-old, raped 10-year-old – Yahoo News

https://news.yahoo.com/lawyer-says-man-accused-killing-160103497.html

Read more
Load More
Next Post
Tonga volcano eruption: What we know so far – Al Jazeera English

Tonga volcano eruption: What we know so far - Al Jazeera English

  • Trending
  • Comments
  • Latest
Vicky White news – latest: Recordings of jailhouse phone calls prove guard’s relationship with Casey White – The Independent

Vicky White news – latest: Recordings of jailhouse phone calls prove guard’s relationship with Casey White – The Independent

The #1 Best Supplement to Keep Your Bones from Aging, Says Dietitian — Eat This Not That – Eat This, Not That

The #1 Best Supplement to Keep Your Bones from Aging, Says Dietitian — Eat This Not That – Eat This, Not That

Horror as goat gives birth to ‘humanoid kid’ with baby-like face

Six times actors really romped in sex scenes that make 365 DNI look tame

Six times actors really romped in sex scenes that make 365 DNI look tame

Shares recover even as growth, inflation fears linger – Reuters.com

Shares recover even as growth, inflation fears linger – Reuters.com

Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN

Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN

Wounded Soldier And Military Dog Reunite After Receiving Purple Hearts

Wounded Soldier And Military Dog Reunite After Receiving Purple Hearts

Exercise Increases Dopamine Release in Mice – Neuroscience News

Exercise Increases Dopamine Release in Mice – Neuroscience News

About Us

Todayheadline the independent news and topics discovery
A home-grown and independent news and topic aggregation . displays breaking news linking to news websites all around the world.

Follow Us

Latest News

Shares recover even as growth, inflation fears linger – Reuters.com

Shares recover even as growth, inflation fears linger – Reuters.com

Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN

Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN

Shares recover even as growth, inflation fears linger – Reuters.com

Shares recover even as growth, inflation fears linger – Reuters.com

Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN

Online posts reveal suspected gunman spent months planning racist attack at a Buffalo supermarket – CNN

Wounded Soldier And Military Dog Reunite After Receiving Purple Hearts

Wounded Soldier And Military Dog Reunite After Receiving Purple Hearts

  • Real Estate
  • Education
  • Parenting
  • Cooking
  • Travel and Tourism
  • Home & Garden
  • Pets
  • Privacy & Policy
  • Contact
  • About

© 2021 All rights are reserved Todayheadline

No Result
View All Result
  • Real Estate
  • Education
  • Parenting
  • Cooking
  • Travel and Tourism
  • Home & Garden
  • Pets
  • Privacy & Policy
  • Contact
  • About

© 2021 All rights are reserved Todayheadline

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Posting....