Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2022-01-16 21:07:11| Engadget

Apple device users appear to be vulnerable to a significant browser privacy flaw. According to 9to5Mac, FingerprintJS has disclosed an exploit that lets attackers obtain your recent browser history, and even some Google account info, from Safari 15 across all supported platforms as well as third-party browsers on iOS 15 and iPadOS 15. The IndexedDB framework (used to store data on many browsers) is violating the "same-origin" policy that prevents documents and scripts from one location (such as a domain or protocol) from interacting with content from another, letting appropriately coded websites deduce Google info from signed-in users as well as histories from open tabs and windows.The flaw only compromises the names of the databases rather than the content itself. However, this would still be enough for a malicious site owner to grab your Google username, discover your profile picture and otherwise learn more about you. The history could also be used to piece together a rudimentary profile of the sites you like. Private browsing won't defeat the exploit, FingerprintJS said.We've asked Apple for comment. FingerprintJS said it reported the issue on November 28th, however, and that Apple hadn't yet addressed it with security patches honoring same-origin policy. Until then, the only solution may be to either use a third-party browser on Macs or block all JavaScript, neither of which is necessarily an option.


Category: Marketing and Advertising

 

Latest from this category

24.04Qualcomm is expanding its next-gen laptop chip line with the Snapdragon X Plus
24.04Windows 11 now comes with its own adware
24.04FTC bans employers from using noncompete clauses
24.04Mercedes-Benz quad-motor G-Class could be the ultimate EV off-roader
24.04The Morning After: Senate passes the bill that could ban TikTok
24.04Mercedes-Benz finally unveils its electric G-Class luxury off-roader
24.04EU's new right-to-repair rules force companies to repair out-of-warranty devices
24.04Senate passes bill that could ban TikTok
Marketing and Advertising »

All news

24.04United States: "Shadow Trading" Is Insider Trading: Jury Establishes Liability In Historic Shadow Trading Case - Lowenstein Sandler
24.04United States: CFIUS Proposes Expanded Enforcement Authorities And Increased Penalties - Akin Gump Strauss Hauer & Feld LLP
24.04United States: EPA Has Now Listed Two PFAS As Hazardous Substances Under CERCLA. Hold Onto Your Hats - Mintz
24.04China: How To Curb The Risk Of Non-use And Invalidation Challenges When It Comes To Trademark Assignment In China - Kangxin
24.04United States: Shadow Trading Expands Potential Insider Trading Liability In S.E.C. v. Panuwat - Cadwalader, Wickersham & Taft LLP
24.04United Arab Emirates: A Comprehensive Overview Of The 2023 Commercial Fraud Law - Awatif Mohammad Shoqi Advocates & Legal Consultancy
24.04UK: Tackling Health And Safety In Sport: A New Era Of Accountability For Governing Bodies And Participants - Shepherd and Wedderburn LLP
24.04United States: IPAS Brewing In Illinois - Dickinson Wright PLLC
More »
Privacy policy . Copyright . Contact form .