{"id":2110,"date":"2022-01-21T04:50:08","date_gmt":"2022-01-21T12:50:08","guid":{"rendered":"https:\/\/www.ssls.com\/blog\/?p=2110"},"modified":"2023-09-27T05:33:45","modified_gmt":"2023-09-27T12:33:45","slug":"safari-15-bug-can-leak-your-personal-information","status":"publish","type":"post","link":"https:\/\/www.ssls.com\/blog\/safari-15-bug-can-leak-your-personal-information\/","title":{"rendered":"Safari 15 bug can leak your personal&nbsp;information"},"content":{"rendered":"\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.ssls.com\/blog\/wp-content\/uploads\/SSL_Blog_Safari-15-bug.png\" alt=\"\" class=\"wp-image-2026\"\/><\/figure>\n\n\n\n<p>Recent findings from FingerprintJS, a browser fingerprinting and fraud detection service, have revealed that a software bug in Safari 15 <a href=\"https:\/\/fingerprintjs.com\/blog\/indexeddb-api-browser-vulnerability-safari-15\/\">can leak your identity<\/a> and allow any website to track your Internet activity. The bug is related to the Apple browser\u2019s implementation of an application programming interface (API) called IndexedDB, which is designed to store data in your browser.&nbsp;<br><\/p>\n\n\n\n<p>Read on to learn more about the API and how exactly it\u2019s leaking this data.&nbsp;<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">What is IndexedDB API?<\/h2>\n\n\n\n<p>Supported and used by many major browsers, IndexedDB API provides client-side (browser) storage that can store significant amounts of data. But what does that mean in practice? Practically speaking, it\u2019s used to save data from websites you visit so that they load faster when you return. It does this by creating a database to store the data for each website you visit. These databases are supposed to be private to each individual site, so that one domain cannot access the database of another. In short, a domain should only access the data that it generated.&nbsp;<br><\/p>\n\n\n\n<p>This practice is known as same-origin policy, an important concept in web application <a href=\"https:\/\/www.ssls.com\/blog\/symantec-ev-ssl-authentication-guide\/\">security<\/a>. It ensures that if you have opened several browser tabs where you\u2019re logged into personal accounts, if you happen to open another tab with a malicious web page, it won\u2019t be able to view or access the data contained in the other tabs.\u00a0<br><\/p>\n\n\n\n<p>The problem with the implementation of IndexedDB API in Safari 15 is that it violates same-origin policy.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How the bug leaks your data<\/h2>\n\n\n\n<p>According to FingerprintJS, during a browser session in Safari 15, IndexedDB API actually creates a new (empty) database with the same name in all other active frames, tabs, and windows. This is a problem because it not only allows any active websites you have open to see the other websites you visit, but it can also reveal user-specific identifiers on websites that require users to be authenticated.&nbsp;<br><\/p>\n\n\n\n<p>A major example is any site that uses Google User ID, such as YouTube, Gmail, or Google Calendar. All of these sites create databases that include the user\u2019s Google User ID, and databases are created for every account the user is logged into. If malicious users have access to this ID, they could potentially use it to reveal a great deal of personal information about the account owner, as well as other online accounts linked to their Google User ID.<br><\/p>\n\n\n\n<p>For an example of this kind of data leak in action, <a href=\"https:\/\/www.youtube.com\/watch?v=Z7dPeGpCl8s&amp;t=95s&amp;ab_channel=FingerprintJS\">check out this video<\/a>.&nbsp;<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What can you do about it?<\/h2>\n\n\n\n<p>For Windows users who use Safari, switch to another web browser. For Safari users on iPadOS and iOS, there\u2019s not much you can do since Apple has banned all third-party browser engines. This means that switching browsers won\u2019t help. FingerprintJS suggests the drastic measure of blocking Javascript by default and only permitting it on trusted sites, however, this isn\u2019t a very practical solution. For now, the best solution is to keep an eye on browser updates and make sure to update yours as soon as Apple resolves the issue.<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent findings from FingerprintJS, a browser fingerprinting and fraud detection service, have revealed that a software bug in Safari 15 can leak your identity and allow any website to track your Internet activity. The bug is related to the Apple browser\u2019s implementation of an application programming interface (API) called IndexedDB, which is designed to store [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2110","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/2110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/comments?post=2110"}],"version-history":[{"count":3,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/2110\/revisions"}],"predecessor-version":[{"id":2608,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/2110\/revisions\/2608"}],"wp:attachment":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/media?parent=2110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/categories?post=2110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/tags?post=2110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}