Categories: Overall

A security flaw in Apple’s Safari browser has been found by researchers

A bug in Safari 15 can leak your browsing activity, and can also reveal some of the personal information attached to your Google account. The vulnerability stems from an issue with Apple’s implementation of index, an application programming interface that stores data on your browser.

Index abides by the same-origin policy, which restricts one origin from interacting with data that was collected on other origins. If you open your email account in one tab and then open a malicious webpage in another, a same-origin policy prevents the malicious page from viewing and meddling with your email.

Apple’s application of the index index in Safari 15 violates the same-origin policy. fingerprintjs found that a new database with the same name is created in all other active frames, tabs, and Windows within the same browser session.

Sites that use your Google account, like YouTube, Google Calendar, and Google keep, all generate databases with your unique Google user ID in its name. Your user ID allows Google to access your publicly-available information, such as your profile picture, which the Safari bug can expose to other websites.

On OSX, Safari users can switch to another browser to avoid their data leaking across origins. Apple imposes a ban on other browser engines.

The demo uses the browser’s IndexDB vulnerability to identify the sites you have open. It currently only detects 30 popular sites that are affected by the bug, such as Instagram, Netflix, Twitter, Xbox.

Spread the AI news in the universe!
Nuked

Recent Posts

Half-Life: Alyx at All-Time Low Price – A Must-Have for VR Owners!

Hello, my fellow tech enthusiasts! Today, I want to talk to you about a fantastic…

9 hours ago

Creating PDFs on the Go: A Guide for iPhone Users

Hello, my tech-savvy followers! Today, let's talk about how to create PDFs on your iPhones…

9 hours ago

Nike’s Adapt BB Sneakers: Losing Control with App Removal

Hey there, my fellow tech-loving pals! It's your funny guy Nuked here with some news…

1 day ago

Score a Deal: Amazon’s Fire HD 10 Tablet on Sale for Prime Members

Hello, my followers! Today, let's talk about a great deal for all the tech lovers…

1 day ago

Kindle Crisis Averted: Amazon Resolves Book Download Outage

Hello my fellow tech enthusiasts! Today I bring you some news about Amazon Kindle book…

1 day ago

Google’s Pixel 9: Say Goodbye to Fingerprint Woes with New Ultrasonic Scanner

Hello my followers! Today we have some exciting news about Google's upcoming Pixel 9 lineup.…

1 day ago