Safari 15 bug can leak your recent browsing activity and personal identifiers

Illustration by Alex Castro / The Verge

A bug in Safari 15 can leak your browsing activity, and can also reveal some of the personal information attached to your Google account, according to findings from FingerprintJS, a browser fingerprinting and fraud detection service (via 9to5Mac). The vulnerability stems from an issue with Apple’s implementation of IndexedDB, an application programming interface (API) that stores data on your browser.

As explained by FingerprintJS, IndexedDB abides by the same-origin policy, which restricts one origin from interacting with data that was collected on other origins — essentially, only the website that generates data can access it. For example, if you open your email account in one tab and then open a malicious webpage in another, the...

Continue reading…



from The Verge - All Posts https://ift.tt/3qvMNm7

Comments

Popular posts from this blog

The Twitter board is reportedly not interested in Elon’s takeover offer

Amazon is acquiring a podcast hosting and monetization platform