时间:2026-04-07 20:16:51 来源:网络整理编辑:探索
A vulnerability in Safari can be exploited to expose your browser history — and possibly eleme
A vulnerability in Safari can be exploited to expose your browser history — and possibly elements of your identity.
Revealed in a Saturday blog post by FingerprintJS, the bug was introduced to Safari 15 via the Indexed Database API(IndexedDB), which is part of Apple's WebKitweb browser development engine. To put it simply, IndexedDB can be used to save data on your computer such as websites you've visited, making them load quicker when you return to them later.
IndexedDB also usually follows the same-origin policysecurity mechanism, which doesn't let websites freely interact with each other unless they have the same domain name (among other requirements). Think of it like being in quarantine and only being allowed to hang out with members of your household. So for example, Netflix can't access IndexedDB's saved data to find out you've been cheating on them with YouTube.
SEE ALSO:How to move Safari's search bar back to the top in iOS 15Unfortunately, the bug revealed by FingerprintJS causes IndexedDB to violate the same-origin policy, exposing data it has collected to websites it didn't collect it from. Even worse, some websites such as those in Google's network use unique user-specific identifiers in the data provided to IndexedDB. This means that, if you're logged into your Google account, the collected data can be used to precisely identify both your browsing history and details of your account. And if you're logged into more than one account, it can figure that out too.
iRobot Roomba Combo i3+ Self-Emptying Robot Vacuum and Mop—$329.99(List Price $599.99)
Samsung Galaxy Tab A9+ 10.9" 64GB Wi-Fi Tablet—$169.99(List Price $219.99)
Apple AirPods Pro 2nd Gen With MagSafe USB-C Charging Case—$189.99(List Price $249.00)
Eero 6 Dual-Band Mesh Wi-Fi 6 System (Router + 2 Extenders)—$149.99(List Price $199.99)
Apple Watch Series 9 (GPS, 41mm, Midnight, S/M, Sports Band)—$299.00(List Price $399.00)
"Not only does this imply that untrusted or malicious websites can learn a user’s identity, but it also allows the linking together of multiple separate accounts used by the same user," wrote FingerprintJS. They also released a demonstrationshowing the type of information the exploit can reveal.
FingerprintJS reported the bugat the end of last November, but Apple still hasn't fixed it. Mashable has reached out to Apple for comment.
All of this is concerning, but there isn't much you can do about it right now. Browsing in Safari's Private mode can mitigate the potential damage, since a private tab can't tell what's going on in any other tabs regardless of whether they're private or public. However it still isn't foolproof.
"[I]f you visit multiple different websites within the same [private] tab, all databases these websites interact with are leaked to all subsequently visited websites," wrote FingerprintJS.
Mac users can avoid the vulnerability by switching from Safari to a different browser, but people on iOS or iPadOS are out of luck. While only Safari has been impacted on Mac, Apple's requirement that all iOS and iPad web browsers use WebKit means the IndexedDB bug has impacted every browser on these systems. The best we can do is either wait for Apple to come out with a patch, switch to an Android, or just log off.
TopicsAppleCybersecurity
Satisfy your Olympics withdrawals with Nike's latest app2026-04-07 19:54
官方:熱刺買斷中衛羅梅羅,轉會費4100萬鎊2026-04-07 19:52
蒿俊閔之所以願意加盟廣州隊 是因為球隊主教練鄭智親自出麵邀約2026-04-07 19:38
AC米蘭隊史今天 :1992年8月30日巴斯滕+馬薩羅破門,第2次獲得意大利超級杯2026-04-07 19:36
Teacher absolutely nails it with new homework policy2026-04-07 19:22
今日足球:國際米蘭vs克雷莫納 富勒姆vs布萊頓2026-04-07 19:02
2010以來五大聯賽射手榜:梅西第一 ,萊萬第四,第三年薪僅200萬2026-04-07 18:52
蒿俊閔之所以願意加盟廣州隊 是因為球隊主教練鄭智親自出麵邀約2026-04-07 18:42
Two states took big steps this week to get rid of the tampon tax2026-04-07 17:45
皇家將貝林厄姆視為莫德裏奇的接班人 ,拜仁與體育總監薩利續約2026-04-07 17:30
Despite IOC ban, Rio crowds get their political messages across2026-04-07 20:14
今晚國米羅馬AC米蘭誰會爆冷 ?吉馬良斯02026-04-07 19:58
從阿森納VS熱刺,到水晶宮VS布倫特 ,這就是英超你死我活的倫敦德比 !2026-04-07 19:54
羅馬諾:切爾西簽戈登的交易很複雜 同時在與巴薩進行戰略博弈2026-04-07 19:33
Samsung Galaxy Note7 teardown reveals the magic behind the phone's iris scanner2026-04-07 19:28
拿走4億巨款卻無法再為國足效力 高拉特近期將恢複巴西國籍2026-04-07 18:49
驚喜 !曝前國腳蒿俊閔加盟廣州隊 力助鄭智率隊保級2026-04-07 18:34
官方 :熱刺買斷中衛羅梅羅,轉會費4100萬鎊2026-04-07 18:33
How Hyperloop One went off the rails2026-04-07 17:45
留下還是離開?多拉多:我很快會說明自己的未來2026-04-07 17:43