Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities SC Media

Developer alleges Alibaba uses audio fingerprinting for web tracking

  • What: Developer raises concerns about potential web tracking via audio fingerprinting on Alibaba's website
  • Impact: Users may be tracked without their knowledge
Read Full Article →

Privacy Developer alleges Alibaba uses audio fingerprinting for web tracking August 24, 2026 Share By SC Staff A developer has raised concerns about Alibaba potentially tracking web users by exploiting audio fingerprinting vulnerabilities in browsers. The issue came to light when the developer noticed his Bluetooth headphones malfunctioning when visiting Alibaba’s website, based on information published by The Register. Software engineer Matt Callaghan discovered that Alibaba's website employed obfuscated audio scripts that generated a waveform and analyzed its output. Although the audio gain was set to zero, preventing users from hearing anything, the WebAudio graph was processed by the browser. This process, Callaghan claims, was sufficient to maintain an active audio path, interfering with his Bluetooth headphones' ability to switch audio sources. Further analysis of the code revealed attempts to collect data such as screen dimensions, device memory, and browser plugins, suggesting a comprehensive device fingerprint. While Firefox stated its anti-fingerprinting technology, introduced in version 118, effectively neutralizes WebAudio-based fingerprinting by grouping users into broad categories, a small number of users may still be uniquely identifiable. Brave also confirmed its browser blocks such tracking methods by default. Other browsers like Safari have similar protections, while Chrome was noted to have fewer built-in defenses against various fingerprinting techniques, according to privacy consultant Alexander Hanff. Source: The Register SC Staff Related Privacy TikTok agrees to $400 million settlement over child privacy SC Staff August 24, 2026 The settlement addresses claims that TikTok illegally collected data from users under 13 and knowingly allowed them to create accounts, violating the Children's Online Privacy Protection Act (COPPA). Active Directory Why Short-Lived Workloads Create Long-Lived Identity Risk SC Media Editorial Intelligence, reviewed by Christopher Ashby August 24, 2026 Static Governance Cannot Keep Pace with Ephemeral Identities Privacy Senator Wyden seeks review of federal law enforcement hacking tools SC Staff August 21, 2026 Wyden has formally requested the U.S. Government Accountability Office (GAO) to conduct a comprehensive inquiry into how agencies such as the FBI, DEA, ICE Homeland Security Investigations, and the Secret Service utilize these sophisticated surveillance technologies. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Anonymization Authenticity Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Geolocation Identity Theft You can skip this ad in 5 seconds

Share this article