Safari 15 bug can leak your recent browsing activity and personal identifiers

Illustration by Alex Castro / The Verge

A bug in Safari 15 can leak your browsing activity, and can also reveal some of the personal information attached to your Google account, according to findings from FingerprintJS, a browser fingerprinting and fraud detection service (via 9to5Mac). The vulnerability stems from an issue with Apple’s implementation of IndexedDB, an application programming interface (API) that stores data on your browser.

As explained by FingerprintJS, IndexedDB abides by the same-origin policy, which restricts one origin from interacting with data that was collected on other origins — essentially, only the website that generates data can access it. For example, if you open your email account in one tab and then open a malicious webpage in another, the...

Continue reading…



from The Verge - All Posts https://ift.tt/3qvMNm7

Comments

Popular posts from this blog

Gemini app finally expands to audio files

Amazon is offering a like-new Kindle Paperwhite 2024 for just $107

Apple Watch Series 8, SE 2, and Ultra hands-on: triple the fun