Apple Safari 15 bug can leak your browsing activity, personal data

A software bug in Apple browser Safari 15 may let any website track your internet activity and even reveal your identity via macOS, iOS and iPadOS 15, according to a new report

Apple
IANS San Francisco
3 min read Last Updated : Jan 17 2022 | 5:49 PM IST

A software bug in Apple browser Safari 15 may let any website track your internet activity and even reveal your identity via macOS, iOS and iPadOS 15, according to a new report. The bug could also expose your Google User ID to other websites.

In this case, private mode viewing in Safari 15 browser is also suspected to be affected by the vulnerability.

FingerprintJS, a browser fingerprinting and fraud detection service, found that the bug stems from an issue with Apple's implementation of IndexedDB, an application programming interface (API) that stores data on your browser.

"IndexedDB is a browser API for client-side storage designed to hold significant amounts of data. It's supported in all major browsers and is very commonly used," FingerprintJS said in a statement.

The report said that more than 30 websites interact with indexed databases directly on their homepage, without any additional user interaction or the need to authenticate.

"We suspect this number to be significantly higher in real-world scenarios as websites can interact with databases on subpages, after specific user actions, or on authenticated parts of the page," said the FingerprintJS team.

Like most modern web browser technologies, IndexedDB is following the same-origin policy.

The same-origin policy is a fundamental security mechanism that restricts how documents or scripts loaded from one origin can interact with resources from other origins.

For example, if you open your email account in one tab and then open a malicious webpage in another, the same-origin policy prevents the malicious page from infecting your email.

"In Safari 15 on macOS, and in all browsers on iOS and iPadOS 15, the IndexedDB API is violating the same-origin policy," FingerprintJS said.

Every time a website interacts with a database, a new (empty) database with the same name is created in all other active frames, tabs, and windows within the same browser session.

Windows and tabs usually share the same session, unless you switch to a different profile, in Chrome for example, or open a private window.This means other websites can see the name of other databases created on other sites, which could contain details specific to your identity.

FingerprintJS reported the leak but there hasn't been an update to Safari yet.

"The fact that database names leak across different origins is an obvious privacy violation. It lets arbitrary websites learn what websites the user visits in different tabs or windows," they said.

--IANS

na/vd

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :Apple cyber security

First Published: Jan 17 2022 | 5:49 PM IST

Next Story