时间:2026-01-07 10:41:14 来源:网络整理编辑:探索
A vulnerability in Safari can be exploited to expose your browser history — and possibly eleme
A vulnerability in Safari can be exploited to expose your browser history — and possibly elements of your identity.
Revealed in a Saturday blog post by FingerprintJS, the bug was introduced to Safari 15 via the Indexed Database API(IndexedDB), which is part of Apple's WebKitweb browser development engine. To put it simply, IndexedDB can be used to save data on your computer such as websites you've visited, making them load quicker when you return to them later.
IndexedDB also usually follows the same-origin policysecurity mechanism, which doesn't let websites freely interact with each other unless they have the same domain name (among other requirements). Think of it like being in quarantine and only being allowed to hang out with members of your household. So for example, Netflix can't access IndexedDB's saved data to find out you've been cheating on them with YouTube.
SEE ALSO:How to move Safari's search bar back to the top in iOS 15Unfortunately, the bug revealed by FingerprintJS causes IndexedDB to violate the same-origin policy, exposing data it has collected to websites it didn't collect it from. Even worse, some websites such as those in Google's network use unique user-specific identifiers in the data provided to IndexedDB. This means that, if you're logged into your Google account, the collected data can be used to precisely identify both your browsing history and details of your account. And if you're logged into more than one account, it can figure that out too.
iRobot Roomba Combo i3+ Self-Emptying Robot Vacuum and Mop—$329.99(List Price $599.99)
Samsung Galaxy Tab A9+ 10.9" 64GB Wi-Fi Tablet—$169.99(List Price $219.99)
Apple AirPods Pro 2nd Gen With MagSafe USB-C Charging Case—$189.99(List Price $249.00)
Eero 6 Dual-Band Mesh Wi-Fi 6 System (Router + 2 Extenders)—$149.99(List Price $199.99)
Apple Watch Series 9 (GPS, 41mm, Midnight, S/M, Sports Band)—$299.00(List Price $399.00)
"Not only does this imply that untrusted or malicious websites can learn a user’s identity, but it also allows the linking together of multiple separate accounts used by the same user," wrote FingerprintJS. They also released a demonstrationshowing the type of information the exploit can reveal.
FingerprintJS reported the bugat the end of last November, but Apple still hasn't fixed it. Mashable has reached out to Apple for comment.
All of this is concerning, but there isn't much you can do about it right now. Browsing in Safari's Private mode can mitigate the potential damage, since a private tab can't tell what's going on in any other tabs regardless of whether they're private or public. However it still isn't foolproof.
"[I]f you visit multiple different websites within the same [private] tab, all databases these websites interact with are leaked to all subsequently visited websites," wrote FingerprintJS.
Mac users can avoid the vulnerability by switching from Safari to a different browser, but people on iOS or iPadOS are out of luck. While only Safari has been impacted on Mac, Apple's requirement that all iOS and iPad web browsers use WebKit means the IndexedDB bug has impacted every browser on these systems. The best we can do is either wait for Apple to come out with a patch, switch to an Android, or just log off.
TopicsAppleCybersecurity
Felix the cat just raised £5000 for charity because she's the hero we all need2026-01-07 09:51
曝國安正式報價韓國國腳薑祥佑 僅差球員本人確認簽字2026-01-07 09:48
國足安心備戰未受場外紛爭影響 磨合陣容敲定首發2026-01-07 09:47
國足助教:感謝中國足協的信任 這是巨大的榮耀2026-01-07 09:34
5 people Tim Cook calls for advice on running the biggest company in the world2026-01-07 09:27
李可:傷病問題已經解決 正在阿森納進行康複治療2026-01-07 09:11
紐卡敲定冬窗第三簽 3000萬鎊購巴西國腳吉馬良斯2026-01-07 09:01
逼宮 ?阿爾特塔飛赴美國麵聖 盼說服老板掏錢引援2026-01-07 08:33
Major earthquake and multiple aftershocks rock central Italy2026-01-07 08:01
吳曦:球迷對興奮點是一種刺激 上一場比賽已成過去2026-01-07 08:00
Despite IOC ban, Rio crowds get their political messages across2026-01-07 10:26
C羅離隊後尤文變陣三前鋒 進攻效率下滑+多線潰敗2026-01-07 09:59
巴薩荷蘭幫失勢!一朝天子一朝臣 皆因硬實力不足2026-01-07 09:51
王大雷:在國家隊除了泰山和海港的人 大家都在討論欠薪2026-01-07 09:27
Airbnb activates disaster response site for Louisiana flooding2026-01-07 09:11
曝郭田雨留洋目標為葡超球隊維澤拉 有中資背景暫列第12位2026-01-07 09:09
費南多社媒轉發心靈雞湯:再堅持一會兒 將迎來勝利2026-01-07 08:32
曝國安正式報價韓國國腳薑祥佑 僅差球員本人確認簽字2026-01-07 08:29
Fake news reports from the Newseum are infinitely better than actual news2026-01-07 08:29
蔣光太:假期一直跟隨體能教練訓練 爭取能零封日本2026-01-07 08:16