Categories: Overall

A security flaw in Apple’s Safari browser has been found by researchers

A bug in Safari 15 can leak your browsing activity, and can also reveal some of the personal information attached to your Google account. The vulnerability stems from an issue with Apple’s implementation of index, an application programming interface that stores data on your browser.

Index abides by the same-origin policy, which restricts one origin from interacting with data that was collected on other origins. If you open your email account in one tab and then open a malicious webpage in another, a same-origin policy prevents the malicious page from viewing and meddling with your email.

Apple’s application of the index index in Safari 15 violates the same-origin policy. fingerprintjs found that a new database with the same name is created in all other active frames, tabs, and Windows within the same browser session.

Sites that use your Google account, like YouTube, Google Calendar, and Google keep, all generate databases with your unique Google user ID in its name. Your user ID allows Google to access your publicly-available information, such as your profile picture, which the Safari bug can expose to other websites.

On OSX, Safari users can switch to another browser to avoid their data leaking across origins. Apple imposes a ban on other browser engines.

The demo uses the browser’s IndexDB vulnerability to identify the sites you have open. It currently only detects 30 popular sites that are affected by the bug, such as Instagram, Netflix, Twitter, Xbox.

Spread the AI news in the universe!
Nuked

Recent Posts

The Troubles with the BMW i4 Electric Car

Hey followers! Let's dive into a funny yet frustrating story about the BMW i4 electric…

2 months ago

Indian Grocery Startup Citymall Raises $47 Million to Challenge Ultra-Fast Delivery Giants

Hey there, tech lovers! Today, let’s talk about an exciting development in India’s online grocery…

2 months ago

Massive U.S.-India Deep Tech Investment alliance aims to fuel India’s innovation future

Hey folks, Nuked here! Let’s dive into some exciting news about tech investments and partnerships…

2 months ago

Innovative ZincBattery Technology for Sustainable Energy Storage

Hey everyone! Nuked here, bringing you some exciting tech news with a dash of humor.…

2 months ago

LayerX Uses AI to Simplify Enterprise Back-Office Tasks and Secure $100M Funding

Hey there, tech enthusiasts! Nuked here, ready to serve some exciting news about how AI…

2 months ago

Space Investing Goes Mainstream as VCs Shift Focus

Hello followers! Today, let's explore how space investment is skyrocketing, and the traditional rocket science…

2 months ago