A vulnerability in Safari can be exploited to expose your browser history — and possibly elements of your identity.
Revealed in a Saturday blog post by FingerprintJS, the bug was introduced to Safari 15 via the Indexed Database API(IndexedDB), which is part of Apple's WebKitweb browser development engine. To put it simply, IndexedDB can be used to save data on your computer such as websites you've visited, making them load quicker when you return to them later.
IndexedDB also usually follows the same-origin policysecurity mechanism, which doesn't let websites freely interact with each other unless they have the same domain name (among other requirements). Think of it like being in quarantine and only being allowed to hang out with members of your household. So for example, Netflix can't access IndexedDB's saved data to find out you've been cheating on them with YouTube.
SEE ALSO: How to move Safari's search bar back to the top in iOS 15Unfortunately, the bug revealed by FingerprintJS causes IndexedDB to violate the same-origin policy, exposing data it has collected to websites it didn't collect it from. Even worse, some websites such as those in Google's network use unique user-specific identifiers in the data provided to IndexedDB. This means that, if you're logged into your Google account, the collected data can be used to precisely identify both your browsing history and details of your account. And if you're logged into more than one account, it can figure that out too.
"Not only does this imply that untrusted or malicious websites can learn a user’s identity, but it also allows the linking together of multiple separate accounts used by the same user," wrote FingerprintJS. They also released a demonstrationshowing the type of information the exploit can reveal.
FingerprintJS reported the bugat the end of last November, but Apple still hasn't fixed it. Mashable has reached out to Apple for comment.
All of this is concerning, but there isn't much you can do about it right now. Browsing in Safari's Private mode can mitigate the potential damage, since a private tab can't tell what's going on in any other tabs regardless of whether they're private or public. However it still isn't foolproof.
"[I]f you visit multiple different websites within the same [private] tab, all databases these websites interact with are leaked to all subsequently visited websites," wrote FingerprintJS.
Mac users can avoid the vulnerability by switching from Safari to a different browser, but people on iOS or iPadOS are out of luck. While only Safari has been impacted on Mac, Apple's requirement that all iOS and iPad web browsers use WebKit means the IndexedDB bug has impacted every browser on these systems. The best we can do is either wait for Apple to come out with a patch, switch to an Android, or just log off.
Copyright © 2023 Powered by
New Safari bug can expose Apple users' browser history and Google account details-鼓盆之戚网
sitemap
文章
588
浏览
491
获赞
91516
Every 2020 candidate's 404 error page, ranked
UPDATE: May 16, 2019, 3:36 p.m. EDT Since this story was published, three more candidates -- Bill deAstronomers saw a long, bright space blast, but it wasn't a supernova
Scientists thought they had a few things figured out about the brightest and most violent space explThe State of 5G: When It's Coming, How Fast It Will Be & The Sci
Although 5G may seem like just another generational upgrade for mobile networks, touting more speedmacOS Sonoma: How to share passwords—even Netflix
The macOS Sonoma update officially rolled out to the masses on Sept. 26, and one of its most usefulBeto O'Rourke livestreamed his haircut. Yes, his haircut.
You can't keep a streaming Beto down.If you didn't think livestreaming a dental appointment was mundCarina Nebula images from James Webb and Hubble telescopes paint stunning cosmic views
A star nursery discovered over 250 years ago will teach astronomers new things about how stars comeBest Echo deal: The Amazon Echo Pop is 70% off plus a month of Amazon Music Unlimited
SAVE 70%:Prime members can score an Amazon Echo Pop for $14.98, plus a free month of Amazon Music UnThe Biggest Tech Fails of the Last Decade
Any organization, be it a multi-billion-dollar corporate behemoth or lowly startup, can launch a hypApple could debut its new laptop chip in a Macbook Pro this year
A few weeks after Apple announced it would start developing its own silicon chip for Mac computers,iPhone 15 Pro overheating reports pop up around the internet
If you just bought a swanky new iPhone 15 Pro, maybe be careful about using it for strenuous activitBest software deal: Adobe Photoshop and Premiere Elements 2023 on sale for 37% off
SAVE $55: As of August 30, the Adobe Photoshop Elements 2023 & Premiere Elements 2023 software fTinder users can now find true love for just $500 per month
Tinder has made searching for love even easier...and obscenely expensive. The dating app announced FGood news everyone, Logan Paul doesn't actually think the Earth is flat
Logan Paul is many things, but thankfully he is not a flat Earther. In a 50-minute, 2-second mockumeGPU Prices Drop Even Further, Sort Of
It's time for our mid-month GPU pricing update and we feel like we say this every month, but honestlElon Musk's X finally agrees to settlement talks with unpaid laid off Twitter employees
Roughly 10 and a half months ago, Elon Musk officially acquired Twitter. In the weeks and months fol