Home RSS Bluetooth Glitch Exposes Alibaba’s Secret Tracking Of Users, Developer Says

Bluetooth Glitch Exposes Alibaba’s Secret Tracking Of Users, Developer Says

0
17

Bluetooth Glitch Exposes Alibaba’s Secret Tracking Of Users, Developer Says

A San Francisco-based developer discovered that Alibaba Group’s AliExpress marketplace secretly hijacked his computer’s audio system through hidden browser scripts, allowing the website to run inaudible sound waves at zero volume to create “fingerprints” used to track devices without relying on cookies. 

The privacy-focused Brave browser revealed in a series of X posts that the AliExpress marketplace was keeping the developer’s computer audio system active through hidden browser scripts, potentially allowing the website to generate a unique identifier for his device.

The issue emerged when the developer’s Bluetooth headphones refused to transfer their audio connection from his computer to his phone while AliExpress was open. A deeper dive of the website’s code showed background scripts maintaining access to the computer’s audio-processing system without producing audible sound.

The scripts allegedly used the browser’s Web Audio API to process signals at zero volume. Small differences in how individual computers handle those signals can be measured and combined into an “audio fingerprint,” allowing websites to recognize devices even when cookies are deleted or blocked.

The developer also found that the scripts collected other device characteristics, including available memory, screen dimensions, and network information.

Here’s what Brave found:

1. Alibaba’s AliExpress was caught using users’ audio systems to track them. AliExpress wasn’t recording users but instead playing a silent sound and measuring how users’ specific devices processed it in order to fingerprint them.

2. Fingerprinting is a way that websites can identify you without cookies. Sites will note details about your device like your screen size or installed fonts. These details are then combined into a unique, persistent “fingerprint” that can be used to track you across the Web.

3. There are slight variations in how each device plays the same audio file due to differences in CPU, sound card, browser, etc. When AliExpress played the silent sound, it measured these small variations to help build fingerprints of users’ devices.

4. This tracking was discovered due to an unexpected side effect. A user with Bluetooth headphones noticed they couldn’t play music on their phone because the headphones were instead playing AliExpress’s silent sound from their PC.

Brave turned what it found into a sales pitch for its browser:

1. For 6+ years, Brave has protected users against audio fingerprinting, and other fingerprinting types, by default. Brave injects random data into the browser’s output so you show a different fingerprint to different sites. This fingerprint also resets across sessions.

2. Trackers are constantly finding new ways to fingerprint your device, so Brave keeps adding new protections. We recently added defenses against GPU fingerprinting, which stops sites from identifying you with your graphics card or drivers.

The findings raise new questions about browser fingerprinting, a stealthy way that uses silent audio processing for covert tracking. 

Tyler Durden
Tue, 08/25/2026 – 19:40

This post was originally published on this site