Categories: Overall

A security flaw in Apple’s Safari browser has been found by researchers

A bug in Safari 15 can leak your browsing activity, and can also reveal some of the personal information attached to your Google account. The vulnerability stems from an issue with Apple’s implementation of index, an application programming interface that stores data on your browser.

Index abides by the same-origin policy, which restricts one origin from interacting with data that was collected on other origins. If you open your email account in one tab and then open a malicious webpage in another, a same-origin policy prevents the malicious page from viewing and meddling with your email.

Apple’s application of the index index in Safari 15 violates the same-origin policy. fingerprintjs found that a new database with the same name is created in all other active frames, tabs, and Windows within the same browser session.

Sites that use your Google account, like YouTube, Google Calendar, and Google keep, all generate databases with your unique Google user ID in its name. Your user ID allows Google to access your publicly-available information, such as your profile picture, which the Safari bug can expose to other websites.

On OSX, Safari users can switch to another browser to avoid their data leaking across origins. Apple imposes a ban on other browser engines.

The demo uses the browser’s IndexDB vulnerability to identify the sites you have open. It currently only detects 30 popular sites that are affected by the bug, such as Instagram, Netflix, Twitter, Xbox.

Spread the AI news in the universe!
Nuked

Recent Posts

IFixit Goes Deep: Unveiling the Inner Workings of Apple’s Vision Pro

Hey there, my fellow tech enthusiasts! It's your favorite funny guy who loves all things…

17 hours ago

Apple’s Vision Pro: Don’t Lose It, Because You Can’t Find It!

Hey there, fellow tech enthusiasts! It's Nuked here, ready to bring you some news about…

2 days ago

Unveiling Apple’s Hidden Surprise: The Mega Lightning Plug in the Vision Pro Headset

Hey there, my fellow tech enthusiasts! It's your funny guy Nuked here, ready to share…

2 days ago

Unveiling the Illusion: The Truth Behind Samsung’s’Fake’ Photos

Hey there, my awesome followers! It's your favorite funny tech guy, Nuked, here to bring…

2 days ago

Apple’s Tim Cook Promises Game-Changing Generative AI Features Coming Soon

Hey there, my fellow tech enthusiasts! It's your funny guy Nuked here, ready to bring…

3 days ago

Grab the Nintendo Switch at a Rare Discount on Amazon: Don’t Miss Out!

Hey there, fellow tech enthusiasts! It's your funny guy Nuked here, ready to bring you…

3 days ago