• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
WebSetNet

WebSetNet

Technology News

  • Technology News
    • Mobile
    • Games
  • Internet Marketing
  • System Admin
    • Windows
    • Linux
    • Mac & Apple
    • Website Scripts
      • Wordpress

Major Apple Safari privacy bug means any websites can access your Google ID, other private data

January 18, 2022 by Martin6

If you care about your privacy you mean need to put down your iPhone, after a serious implementation bug in Safari means any website is able to read some of your private data and recent browsing history, even when using Private Browsing mode.

The issue is with how Safari implements IndexedDB, a browser-based database commonly used by web apps. Most browsers create a new instance of IndexedDB for each website, which can only be accessed from that website.

Safari however creates empty versions of the IndexedDB created by each web page in each other web page, meaning for IndexedDB Safari does not respect same-origin policy properly.

Even though the shadow copies of IndexedDB created for other web pages are empty, they still have the same name as the actual database created by the original web app, which can leak private information. The mere presence of the database will let other web pages know that you visited another website, for example, the presence of the Netflix IndexedDB could tell Amazon that you are a Netflix user. Even worse, however, the name of the database may leak your credentials. The name of the database for Google apps (such as Gmail or YouTube) include your GoogleID for example, which can be used to access your publicly-available information, such as your profile picture.

The bug was discovered and reported by FingerprintJS on the 28th of November, but so far Apple has not taken any action.

You can test out the issue at FingerprintJS’s proof of concept website here, which will check if you visited 30 different major websites recently.

On macOS users can and should use an alternate browser, but on iOS all browsers use the Safari web engine, meaning all iPhone users have no mitigation except to stop using the browser on their phone.

Watch FingerprintJS’s explainer video below:

via the Verge

Related posts:

  1. New iPhone firmware fixes audio and haptic feedback issues in iPhone 7
  2. A Complete List Of Windows Stop Error Codes (Bug Check)
  3. Safari App: The Ultimate Guide
  4. How to identify which iPhone model you’ve got
  5. iPhone X vs iPhone 8
  6. Pokémon Types, Strengths & Weaknesses – Win Your Battles in Pokémon GO
  7. 40 Clever 404 Error Pages From Real Websites
  8. How to Clear Any Web Browser’s History
  9. Best iPhone 8, 7, 6 and SE tips and tricks: Get more from your Touch ID iPhone
  10. Apple iPhone 12 and 12 Pro release date, rumours, news and features

Filed Under: Mac & Apple

Primary Sidebar

Trending

  • How to fix Windows Update Error 80244019
  • Windows 10 Update keeps failing with error 0x8007001f – 0x20006
  • How To Change Netflix Download Location In Windows 10
  • Troubleshoot Outlook “Not implemented” Unable to Send Email Error
  • How do I enable or disable Alt Gr key on Windows 10 keyboard
  • How To Install Android App APK on Samsung Tizen OS Device
  • 3 Ways To Open PST File Without Office Outlook In Windows 10
  • FIX: Windows Update error 0x800f0986
  • How to Retrieve Deleted Messages on Snapchat
  • Latest Samsung Galaxy Note 20 leak is a spec dump revealing key features
  • Install Android 7.0 Nougat ROM on Galaxy Core 2 SM-G355H
  • 192.168.1.1 Login, Admin Page, Username, Password | Wireless Router Settings
  • Websites to Watch Movies Online – 10+ Best Websites Without SignUp/Downloading
  • How to Backup SMS Messages on Your Android Smartphone
  • How to delete a blank page at the end of a Microsoft Word document
  • Fix: The Disc Image File Is Corrupted Error In Windows 10
  • Android 11 Custom ROM List – Unofficially Update Your Android Phone!
  • Samsung Galaxy Z Fold 3 could be scheduled for June 2021, with S Pen support

Footer

Tags

Amazon amazon prime amazon prime video Apple Application software epic games Galaxy Note 20 Galaxy S22 Plus Galaxy S22 Ultra Google Sheets headphones Huawei icloud Instagram instant gaming ip address iPhone iphone 12 iphone 13 iphone 13 pro max macOS Microsoft Microsoft Edge Mobile app office 365 outlook Pixel 6 Samsung Galaxy Samsung Galaxy Book 2 Pro 360 Samsung Galaxy Tab S8 Smartphone speedtest speed test teams tiktok Twitter vpn WhatsApp whatsapp web Windows 10 Windows 11 Changes Windows 11 Release Windows 11 Update Windows Subsystem For Android Windows 11 Xiaomi

Archives

  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org