时间:2026-05-23 02:10:29 来源:网络整理编辑:探索
A vulnerability in Safari can be exploited to expose your browser history — and possibly eleme
A vulnerability in Safari can be exploited to expose your browser history — and possibly elements of your identity.
Revealed in a Saturday blog post by FingerprintJS, the bug was introduced to Safari 15 via the Indexed Database API(IndexedDB), which is part of Apple's WebKitweb browser development engine. To put it simply, IndexedDB can be used to save data on your computer such as websites you've visited, making them load quicker when you return to them later.
IndexedDB also usually follows the same-origin policysecurity mechanism, which doesn't let websites freely interact with each other unless they have the same domain name (among other requirements). Think of it like being in quarantine and only being allowed to hang out with members of your household. So for example, Netflix can't access IndexedDB's saved data to find out you've been cheating on them with YouTube.
SEE ALSO:How to move Safari's search bar back to the top in iOS 15Unfortunately, the bug revealed by FingerprintJS causes IndexedDB to violate the same-origin policy, exposing data it has collected to websites it didn't collect it from. Even worse, some websites such as those in Google's network use unique user-specific identifiers in the data provided to IndexedDB. This means that, if you're logged into your Google account, the collected data can be used to precisely identify both your browsing history and details of your account. And if you're logged into more than one account, it can figure that out too.
iRobot Roomba Combo i3+ Self-Emptying Robot Vacuum and Mop—$329.99(List Price $599.99)
Samsung Galaxy Tab A9+ 10.9" 64GB Wi-Fi Tablet—$169.99(List Price $219.99)
Apple AirPods Pro 2nd Gen With MagSafe USB-C Charging Case—$189.99(List Price $249.00)
Eero 6 Dual-Band Mesh Wi-Fi 6 System (Router + 2 Extenders)—$149.99(List Price $199.99)
Apple Watch Series 9 (GPS, 41mm, Midnight, S/M, Sports Band)—$299.00(List Price $399.00)
"Not only does this imply that untrusted or malicious websites can learn a user’s identity, but it also allows the linking together of multiple separate accounts used by the same user," wrote FingerprintJS. They also released a demonstrationshowing the type of information the exploit can reveal.
FingerprintJS reported the bugat the end of last November, but Apple still hasn't fixed it. Mashable has reached out to Apple for comment.
All of this is concerning, but there isn't much you can do about it right now. Browsing in Safari's Private mode can mitigate the potential damage, since a private tab can't tell what's going on in any other tabs regardless of whether they're private or public. However it still isn't foolproof.
"[I]f you visit multiple different websites within the same [private] tab, all databases these websites interact with are leaked to all subsequently visited websites," wrote FingerprintJS.
Mac users can avoid the vulnerability by switching from Safari to a different browser, but people on iOS or iPadOS are out of luck. While only Safari has been impacted on Mac, Apple's requirement that all iOS and iPad web browsers use WebKit means the IndexedDB bug has impacted every browser on these systems. The best we can do is either wait for Apple to come out with a patch, switch to an Android, or just log off.
TopicsAppleCybersecurity
Honda's all2026-05-23 02:07
尷尬!武磊第90分鍾才登場 無戰術效果僅1次觸球2026-05-23 01:47
英媒:曼聯中場疲軟是C羅造成的 索帥很難能解決2026-05-23 01:23
申花低調出征反客為主 晉級足協杯8強移師大連備戰2026-05-23 01:21
Here's what 'Game of Thrones' actors get up to between takes2026-05-23 00:32
英媒列曼聯潛在新帥 :孔蒂齊祖領銜 竟然還有C羅2026-05-23 00:22
津門虎曾對足協杯寄予很大希望 淘汰後將放假至23日2026-05-23 00:16
女足國門 :有出國踢球的想法 每天都在學習英語2026-05-23 00:05
J.K. Rowling makes 'Harry Potter' joke about Olympics event2026-05-22 23:56
滄州VS深足首發:阿奇姆彭搭卡爾德克 王永珀先發2026-05-22 23:47
Aly Raisman catches Simone Biles napping on a plane like a champion2026-05-23 01:52
愛拚才會贏 !申花需要這樣的血性 置之死地而後生2026-05-23 01:37
萊科:陳序煌有望成為非常好的球員 球隊展現出個性2026-05-23 01:30
德布勞內:金球獎投票給萊萬 我會看近兩年的表現2026-05-23 01:02
Despite IOC ban, Rio crowds get their political messages across2026-05-23 01:02
郜林腸胃炎需手術已退出足協杯 深足轉場大連迎戰申花2026-05-23 00:46
卡拉斯科 :中國球隊踢馬競會輸N比零 那是另一種足球2026-05-23 00:18
搜狐體育連線宋承良:國足現在是弱弱組合 下課對李鐵是解脫2026-05-22 23:58
Metallica to seek and destroy your eardrums with new album this fall2026-05-22 23:55
深足戰滄州可派出最強鋒線 實力+士氣均遠勝對手2026-05-22 23:38