Daily Expert News
No Result
View All Result
Sunday, June 26, 2022
  • Home
  • World
  • Economy
  • Business
  • Markets
  • Arts & Culture
  • Education & Career
  • India
  • Politics
  • Top Stories
Daily Expert News
  • Home
  • World
  • Economy
  • Business
  • Markets
  • Arts & Culture
  • Education & Career
  • India
  • Politics
  • Top Stories
No Result
View All Result
Daily Expert News
No Result
View All Result
  • Home
  • World
  • Economy
  • Business
  • Markets
  • Arts & Culture
  • Education & Career
  • India
  • Politics
  • Top Stories
Home Uncategorized

Safari 15 bug can expose your browsing activity and personal identifiers

by Nick Erickson
January 17, 2022
in Uncategorized
130 3
0
Safari 15 Security Flaw Discovered That Can Leak Your Browsing Activity, Personal Identity
152
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT


Safari 15 turns out to have a vulnerability that leaks your browsing activity and even allows malicious parties to know your identity. The issue arose due to a bug introduced in the implementation of IndexedDB, which works as an Application Programming Interface (API) to store structured data. Users running the latest version of macOS and iOS and iPadOS are affected by the vulnerability. While macOS users can overcome the impact by switching to a third-party browser, iPhone or iPad users have no solution at this time.

As initially reported by 9to5Mac, fingerprint and fraud detection company FingerprintJS has discovered the IndexedBD vulnerability affecting Safari 15. The API follows the same-origin policy which is intended to prevent documents and scripts loaded from one origin. , are used to interact with sources of a different origin. This helps a web browser secure your session on one tab from the website you opened on the other tab.

However, FingerprintJS researchers have found that Apple’s implementation of IndexedDB is against policy. This results in the loophole that an attacker can exploit to gain access to your browsing activity or identity associated with your Google account.

ADVERTISEMENT

“Every time a website interacts with a database, a new (empty) database with the same name is created in all other active frames, tabs and windows within the same browser session,” the researchers said, explaining the vulnerability.

The flaw allows hackers to learn which websites you visit in different tabs or windows. It also exposes your Google user ID to websites other than the one where you are signed in with your Google account. The Google User ID allows websites to access your personally identifiable information, including your profile picture. Ultimately, hackers could see those identifiers by exploiting the Safari vulnerability.

FingerprintJS claims that the number of websites that can communicate and access users’ browsing activity and personal identifiers can be significant. To demonstrate the error, the researchers also released a proof-of-concept.

You can use the demo on your Mac, iPhone or iPad with Safari 15 to view the vulnerability. It is currently detecting popular sites including Alibaba, Instagram, Twitter and Xbox to suggest how the database could be leaked from one site to another. However, the problem is not limited to this one and can also affect users who visit other sites.

Users switching to private mode in Safari 15 may reduce the amount of information available through the leak, as private browsing sessions in the browser are limited to a single tab. However, you will end up leaking your data if you visit multiple websites in a row in the same tab.

Mac users can nevertheless switch to a third-party browser, such as Google Chrome or Mozilla Firefox, to close the security loophole.

However, on iOS, the problem is not just limited to Safari and cannot be solved by going to Chrome or any other third-party browser. This is because Apple does not allow iOS web browsers to use a third-party browser engine on iPhone and iPad.

Users can limit data breaches by disabling JavaScript in their browser for the time being. But that will affect their experience as most sites today use JavaScript to provide modern browsing.

ADVERTISEMENT

FingerprintJS reported the issue to the WebKit Bug Tracker on November 28. However, the error still exists.

ADVERTISEMENT

Gadgets 360 has reached out to Apple to comment on the vulnerability and if it is working on a fix. This article will be updated when the company responds.

Vulnerabilities affecting Safari are not new. Last year, Apple had to re-release its browser to fix security vulnerabilities and bugs introduced by a previous update. The latest Safari build (version 15.2) released in December also fixed six known WebKit vulnerabilities that existed in previous versions that could allow attackers to maliciously access user data.


Check out the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2022 hub.

Tags: ActivitybrowsingBugDailyExpertNewsexposeidentifierspersonalSafari

Get real time update about this post categories directly on your device, subscribe now.

Unsubscribe
ADVERTISEMENT

Related Posts

Young Jugraj Singh beats hat-trick as India beats South Africa 10-2 in FIH Pro League Hockey | Hockey News
Uncategorized

Harmanpreet Singh scores four goals in India’s 10-2 smashing of South Africa in FIH Pro League Hockey | Hockey News

February 13, 2022
Review: An audition season begins at the Philharmonic
Uncategorized

Review: An audition season begins at the Philharmonic

February 13, 2022
Good way to good taste
Uncategorized

Good way to good taste

February 13, 2022
Good way to good taste
Uncategorized

Good way to good taste

February 13, 2022
What to cook this week
Uncategorized

What to cook this week

February 13, 2022
Sigal Barsade, 56, dies; Argued it's okay to show emotions at work
Uncategorized

Sigal Barsade, 56, dies; Argued it’s okay to show emotions at work

February 13, 2022
  • Trending
  • Comments
  • Latest
This optical illusion has a revelation about your brain and eyes

This optical illusion has a revelation about your brain and eyes

June 6, 2022
NDTV Coronavirus

Viral video: Chinese woman pinned down, Covid test carried out by force

May 5, 2022
Hundreds In Sarees At UK

Hundreds of sarees at Britain’s Royal Ascot Horse Race to help Indian weavers

June 16, 2022
Sabrina's parents love her. But the meltdowns are too many.

Sabrina’s parents love her. But the meltdowns are too many.

June 1, 2022

Hello world!

0
NDTV News

IT startup Fareye aims to change Unicorn within a year, founder says

0
How did Stephanie Murphy, a holdout on Biden's agenda, help save it?

How did Stephanie Murphy, a holdout on Biden’s agenda, help save it?

0
How did Stephanie Murphy, a holdout on Biden's agenda, help save it?

How did Stephanie Murphy, a holdout on Biden’s agenda, help save it?

0
Ireland vs India live score over 1st T20I T20 6 10 updates | Cricket News

Ireland vs India live score over 1st T20I T20 6 10 updates | Cricket News

June 26, 2022
Wimbledon 2022: Serena Williams returns to grand slam action as Rafael Nadal and Novak Djokovic headline the men's draw

Wimbledon 2022: Serena Williams returns to grand slam action as Rafael Nadal and Novak Djokovic headline the men’s draw

June 26, 2022

Ireland vs India live score over 1st T20I T20 11 15 updates | Cricket News

June 26, 2022
Biden's new job is to prepare allies for a long conflict in Ukraine.

Biden’s new job is to prepare allies for a long conflict in Ukraine.

June 26, 2022
ADVERTISEMENT

Recent News

Ireland vs India live score over 1st T20I T20 6 10 updates | Cricket News

Ireland vs India live score over 1st T20I T20 6 10 updates | Cricket News

June 26, 2022
Wimbledon 2022: Serena Williams returns to grand slam action as Rafael Nadal and Novak Djokovic headline the men's draw

Wimbledon 2022: Serena Williams returns to grand slam action as Rafael Nadal and Novak Djokovic headline the men’s draw

June 26, 2022

Categories

  • Africa
  • Americas
  • art-design
  • Arts
  • Asia Pacific
  • Astrology News
  • books
  • Books News
  • Business
  • Cricket
  • Cryptocurrency
  • Dance
  • Dining and Wine
  • Economy
  • Education & Career
  • Europe
  • Fashion
  • Food
  • Football
  • Gadget
  • Gaming
  • Golf
  • Health
  • Hot News
  • India
  • Indians Abroad
  • Lifestyle
  • Markets
  • Middle East
  • Most Shared
  • Motorsport
  • Movie
  • Music
  • New York
  • Opinion
  • Politics
  • press release
  • Real Estate
  • Review
  • Science & Space
  • Sports
  • Sunday Book Review
  • Tax News
  • Technology
  • Television
  • Tennis
  • Theater
  • Top Movie Reviews
  • Top Stories
  • Travel
  • Uncategorized
  • Web Series
  • World

Site Navigation

  • Home
  • Advertisement
  • Contact Us
  • Privacy & Policy
  • Other Links

We bring you the Breaking News,Latest Stories,World News, Business News, Political News, Technology News, Science News, Entertainment News, Sports News, Opinion News and much more from all over the world

©Copyright DailyExpertNews 2022

No Result
View All Result
  • Contact Us
  • Home
  • Top Stories
  • World
  • Economy
  • Business
  • Opinion
  • Markets
  • India
  • Education & Career
  • Arts
  • Advertisement
  • Tax News
  • Markets

©Copyright DailyExpertNews 2022

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.