A vulnerability in Safari can be exploited to expose your browser history — and possibly elements of your identity.
Revealed in a Saturday blog post by FingerprintJS, the bug was introduced to Safari 15 via the Indexed Database API(IndexedDB), which is part of Apple's WebKitweb browser development engine. To put it simply, IndexedDB can be used to save data on your computer such as websites you've visited, making them load quicker when you return to them later.
IndexedDB also usually follows the same-origin policysecurity mechanism, which doesn't let websites freely interact with each other unless they have the same domain name (among other requirements). Think of it like being in quarantine and only being allowed to hang out with members of your household. So for example, Netflix can't access IndexedDB's saved data to find out you've been cheating on them with YouTube.
SEE ALSO: How to move Safari's search bar back to the top in iOS 15Unfortunately, the bug revealed by FingerprintJS causes IndexedDB to violate the same-origin policy, exposing data it has collected to websites it didn't collect it from. Even worse, some websites such as those in Google's network use unique user-specific identifiers in the data provided to IndexedDB. This means that, if you're logged into your Google account, the collected data can be used to precisely identify both your browsing history and details of your account. And if you're logged into more than one account, it can figure that out too.
"Not only does this imply that untrusted or malicious websites can learn a user’s identity, but it also allows the linking together of multiple separate accounts used by the same user," wrote FingerprintJS. They also released a demonstrationshowing the type of information the exploit can reveal.
FingerprintJS reported the bugat the end of last November, but Apple still hasn't fixed it. Mashable has reached out to Apple for comment.
All of this is concerning, but there isn't much you can do about it right now. Browsing in Safari's Private mode can mitigate the potential damage, since a private tab can't tell what's going on in any other tabs regardless of whether they're private or public. However it still isn't foolproof.
"[I]f you visit multiple different websites within the same [private] tab, all databases these websites interact with are leaked to all subsequently visited websites," wrote FingerprintJS.
Mac users can avoid the vulnerability by switching from Safari to a different browser, but people on iOS or iPadOS are out of luck. While only Safari has been impacted on Mac, Apple's requirement that all iOS and iPad web browsers use WebKit means the IndexedDB bug has impacted every browser on these systems. The best we can do is either wait for Apple to come out with a patch, switch to an Android, or just log off.
Copyright © 2023 Powered by
New Safari bug can expose Apple users' browser history and Google account details-啜英咀华网
sitemap
文章
3994
浏览
66
获赞
62128
HBO Max vs. HBO Go and HBO Now: What makes each service different
There are now three streaming services with HBO's name on them. Wednesday marked the official launchSpotify takes down thousands of songs generated by AI startup Boomy
Bots beware, Spotify is cracking down on artificial streaming. Spotify took down tens of thousands oGmail gets a blue checkmark to thwart phishing attempts
Here's a blue checkmark that's actually useful: Gmail has launched a new way to identify the authentVolvo EX30 is the company's smallest electric SUV
Volvo's got a new electric SUV coming. The company hasn't given us much, though, beyond the name &ndAOC calls out Kushner: ‘What's next, putting nuclear codes in Instagram DMs?’
It's a cold day in government hell when Instagram DMs get a shoutout at a House Oversight CommitteeCharles Gross comparing two Birkins goes viral on TikTok
The pink sauce craze wasn't the only thing sparking conversation on the clock app this week. CharlesWho owns the rights to your face?
Last year, I received an Instagram DM from someone I was friends with in college. It had been a coupTikTok chef Bottoms Digest claims Postmates ripped off bottom
Last Thursday, Alex Hall was set to post a new cooking tutorial on The Bottoms Digest, a bottom-frieIt's way too easy to accidentally reply to Instagram Stories
I used to love Instagram Stories.After long days at work, mindlessly tapping through Stories on theTikTok is bringing back the '00s digital camera
This Halloween, in the midst of Wordle-inspired costumes and general mayhem, something stood out toAt Google I/O 2023, Search gets an AI overhaul
At Google I/O 2023, the company announced major generative AI updates to its core Search product.NowBing now has 100 million daily users thanks to its AI chatbot
They said it couldn't be done, but Bing now has 100 million daily users. Microsoft's corporate viceThe 'Avengers' cast are arguing over a stolen pillow on Twitter
Admit it: if you got the chance to spend time on the movie set of one of the world's biggest film frApple bans ChatGPT use by employees, report says
Apple employees will reportedly be restricted from using ChatGPT and other artificial intelligence tCharles Gross comparing two Birkins goes viral on TikTok
The pink sauce craze wasn't the only thing sparking conversation on the clock app this week. Charles