时间:2025-11-22 03:26:39 来源:网络整理编辑:探索
A vulnerability in Safari can be exploited to expose your browser history — and possibly eleme
A vulnerability in Safari can be exploited to expose your browser history — and possibly elements of your identity.
Revealed in a Saturday blog post by FingerprintJS, the bug was introduced to Safari 15 via the Indexed Database API(IndexedDB), which is part of Apple's WebKitweb browser development engine. To put it simply, IndexedDB can be used to save data on your computer such as websites you've visited, making them load quicker when you return to them later.
IndexedDB also usually follows the same-origin policysecurity mechanism, which doesn't let websites freely interact with each other unless they have the same domain name (among other requirements). Think of it like being in quarantine and only being allowed to hang out with members of your household. So for example, Netflix can't access IndexedDB's saved data to find out you've been cheating on them with YouTube.
SEE ALSO:How to move Safari's search bar back to the top in iOS 15Unfortunately, the bug revealed by FingerprintJS causes IndexedDB to violate the same-origin policy, exposing data it has collected to websites it didn't collect it from. Even worse, some websites such as those in Google's network use unique user-specific identifiers in the data provided to IndexedDB. This means that, if you're logged into your Google account, the collected data can be used to precisely identify both your browsing history and details of your account. And if you're logged into more than one account, it can figure that out too.
iRobot Roomba Combo i3+ Self-Emptying Robot Vacuum and Mop—$329.99(List Price $599.99)
Samsung Galaxy Tab A9+ 10.9" 64GB Wi-Fi Tablet—$169.99(List Price $219.99)
Apple AirPods Pro 2nd Gen With MagSafe USB-C Charging Case—$189.99(List Price $249.00)
Eero 6 Dual-Band Mesh Wi-Fi 6 System (Router + 2 Extenders)—$149.99(List Price $199.99)
Apple Watch Series 9 (GPS, 41mm, Midnight, S/M, Sports Band)—$299.00(List Price $399.00)
"Not only does this imply that untrusted or malicious websites can learn a user’s identity, but it also allows the linking together of multiple separate accounts used by the same user," wrote FingerprintJS. They also released a demonstrationshowing the type of information the exploit can reveal.
FingerprintJS reported the bugat the end of last November, but Apple still hasn't fixed it. Mashable has reached out to Apple for comment.
All of this is concerning, but there isn't much you can do about it right now. Browsing in Safari's Private mode can mitigate the potential damage, since a private tab can't tell what's going on in any other tabs regardless of whether they're private or public. However it still isn't foolproof.
"[I]f you visit multiple different websites within the same [private] tab, all databases these websites interact with are leaked to all subsequently visited websites," wrote FingerprintJS.
Mac users can avoid the vulnerability by switching from Safari to a different browser, but people on iOS or iPadOS are out of luck. While only Safari has been impacted on Mac, Apple's requirement that all iOS and iPad web browsers use WebKit means the IndexedDB bug has impacted every browser on these systems. The best we can do is either wait for Apple to come out with a patch, switch to an Android, or just log off.
TopicsAppleCybersecurity
Samsung Galaxy Note7 teardown reveals the magic behind the phone's iris scanner2025-11-22 03:25
本澤馬米利唐傷退 ,皇馬22025-11-22 02:45
直擊詹皇衝擊3萬分失敗:遭球迷狂噓 談換帥有遲疑(詹姆斯是nba最厲害的嗎)2025-11-22 02:33
無愧墨爾本之王!德約創曆史斬獲澳網第10冠+大滿貫22冠(德約獲大滿貫27連勝)2025-11-22 02:29
You can now play 'Solitaire' and 'Tic2025-11-22 02:26
毫無辦法!盤點NBA最難防守的十名球星:科比與詹姆斯上榜 !(詹姆斯不僅是球員)2025-11-22 02:17
現役NBA帶動隊友最強的十名球星:自帶進攻體係 !(詹姆斯的超遠三分是真的嗎)2025-11-22 02:07
2023年印尼羽毛球大師賽2025-11-22 00:46
You can now play 'Solitaire' and 'Tic2025-11-22 00:45
難以限製!盤點NBA得分能力最強的十大球星:科比與詹姆斯上榜 !(詹姆斯場均幾個三分)2025-11-22 00:43
Metallica to seek and destroy your eardrums with new album this fall2025-11-22 02:55
2023冬季轉會窗盤點:英超最壕 、切爾西最闊綽、恩佐最貴2025-11-22 02:37
國羽2冠2亞收官 !女雙新組合首秀便奪冠 ,混雙包攬冠亞軍男雙丟冠2025-11-22 02:36
今日賽事 :英超(切爾西vs曼城)2025-11-22 02:36
Whyd voice2025-11-22 02:36
現役球員誰將跟隨詹姆斯的步伐率先衝破3萬分大關 ?(發推稱讚18年詹姆斯的球星)2025-11-22 02:01
如何評價費德勒時隔五年106天重返世界第一?(德約四大滿貫戰績)2025-11-22 01:46
從5中0到3萬分 天王逆襲的背後是什麽(詹姆斯的三分能力)2025-11-22 01:43
U.S. pole vaulter skids to a halt for national anthem2025-11-22 01:41
從5中0到3萬分 天王逆襲的背後是什麽(詹姆斯的三分能力)2025-11-22 00:46