Apple Prepares Fix for Safari Bug Allowing Websites to Decipher Your Recent Browsing Activity

Over the weekend, we reported on a bug in WebKit's implementation of a JavaScript API called IndexedDB that can reveal your recent browsing history and even your identity, according to browser fingerprinting service FingerprintJS.

safari icon blue banner
Apple has since prepared a fix for the bug, according to a WebKit commit on GitHub, but the fix will not be available to users until Apple releases macOS Monterey, iOS 15, and iPadOS 15 updates with an updated version of Safari. Apple declined to comment when asked to provide a timeframe for a fix being released to the public.

The bug allows any website that uses IndexedDB for client-side data storage to access the names of IndexedDB databases generated by other websites during a user's browsing session. The bug could allow one website to track other websites the user visits in different tabs or windows, as the database names are often specific to each website, and sometimes the database names contain user-specific identifiers that could reveal a user's identity.

FingerprintJS has a live demo of the bug, which affects newer versions of browsers using Apple's open source browser engine WebKit, including Safari 15 for macOS and Safari on all versions of iOS 15 and iPadOS 15. The bug also affects third-party browsers like Chrome and Edge on iOS 15 and iPadOS 15, as Apple requires all iPhone and iPad browsers to use WebKit.

The bug does not affect Safari 14 for macOS or any browser on iOS 14 and iPadOS 14, according to FingerprintJS, which has a blog post with more details.

Tag: Safari

Popular Stories

New Things Your iPhone Can Do in iOS 18

18 New Things Your iPhone Can Do in iOS 18.2

Wednesday November 13, 2024 2:09 am PST by
Apple is set to release iOS 18.2 next month, bringing the second round of Apple Intelligence features to iPhone 15 Pro and iPhone 16 models. This update brings several major advancements to Apple's AI integration, including completely new image generation tools and a range of Visual Intelligence-based enhancements. There are a handful of new non-AI related feature controls incoming as well....
M4 MacBook Pros Thumb

M4 MacBook Pro Uses Quantum Dot Display Technology

Thursday November 14, 2024 4:19 pm PST by
The M4 MacBook Pro models feature quantum dot display technology, according to display analyst Ross Young. Apple used a quantum dot film instead of a red KSF phosphor film, a change that provides more vibrant, accurate color results. Young says that Apple has opted for KSF for prior MacBook Pro models because it doesn't use toxic element cadmium (typical for quantum dot) and is more...
AirPods Crackling Feature

Apple Customers Sue Over Unfixed AirPods Pro Crackling Issue

Wednesday November 13, 2024 11:01 am PST by
A trio of Apple customers this month filed a class action lawsuit against Apple, accusing the Cupertino company of violating California consumer protection laws and false advertising for continuing to sell AirPods Pro models that had ongoing issues with crackling or static sounds. A few months after the AirPods Pro came out in October 2019, buyers began to complain about crackling, rattling, ...
google gemini

Google Releases Standalone Gemini AI App for iPhone

Thursday November 14, 2024 2:54 am PST by
Google has launched its dedicated Gemini artificial intelligence app for iPhone users, expanding beyond the previous limited integration within the main Google app. The standalone app offers enhanced functionality, including support for Gemini Live and iOS-specific features like Dynamic Island integration. The new app allows iPhone users to interact with Google's AI through text or voice...
maxresdefault

M4 Max MacBook Pro: Real-World Usage Tests

Wednesday November 13, 2024 11:59 am PST by
Apple last week replaced the M3 Max MacBook Pro with the new M4 Max MacBook Pro, and we picked up one of the new high-end MacBook Pro machines to see how it compares to the prior model with both benchmarks and real-world tests. We tested an M4 Max with a 16-core CPU, 40-core GPU, and 48GB RAM against an M3 Max MacBook Pro with similar specs. The two machines look similar, but the display on...
iphone passcode green

iOS 18 Security Feature Causes iPhone to Reboot After Three Days of Inactivity

Thursday November 14, 2024 2:19 pm PST by
With iOS 18, Apple introduced a feature that causes the iPhone to reboot every three days, security researchers have confirmed (via TechCrunch). In a demo video, security researcher Jiska Classen proved that an iPhone left untouched for 72 hours will automatically restart, and Graykey manufacturer also Magnet Forensics wrote a blog post about the feature. After a reboot, an iPhone is more...

Top Rated Comments

ouimetnick Avatar
37 months ago

but the fix will not be available to users until Apple releases macOS Monterey, iOS 15, and iPadOS 15 updates with an updated version of Safari.
Why can't we have Safari separated from the OS? I didn't have to update macOS for iTunes updates. Never had to update iOS for updates to Pages, Numbers, Keynote, etc.

They do update Safari separate from macOS on older versions of macOS.. Why can't the same be done with the latest/current release of macOS (and iOS/iPadOS)?
Score: 17 Votes (Like | Disagree)
TheYayAreaLiving ?️ Avatar
37 months ago

What do you mean Apple is preparing for a fix?

Apple just issued a fix for macOS and users can get it right here ('https://www.mozilla.org/en-US/firefox/new/') :p
I’m a big fan of Mozilla, Firefox browser. Been using it for years. Possibly a decade. It's too bad I'm addicted to Safari. But Firefox is my 2nd go-to.

Good suggestion though. ?☝️
Score: 14 Votes (Like | Disagree)
KaliYoni Avatar
37 months ago

The bug does not affect Safari 14 for macOS or any browser on iOS 14 and iPadOS 14
Yet again, upgrading right when a new macOS or iOS is released causes major problems for users! If I could get Tim Cook to do one thing, it would be to stop the forced annual releases of OS's. It's not like Apple would take a sales revenue hit from stretching out releases to 18 or 24 months...
Score: 13 Votes (Like | Disagree)
sw1tcher Avatar
37 months ago
What do you mean Apple is preparing for a fix?

Apple just issued a fix for macOS and users can get it right here ('https://www.mozilla.org/en-US/firefox/new/') :p
Score: 13 Votes (Like | Disagree)
diamondsw Avatar
37 months ago

Why can't we have Safari separated from the OS? I didn't have to update macOS for iTunes updates. Never had to update iOS for updates to Pages, Numbers, Keynote, etc.

They do update Safari separate from macOS on older versions of macOS.. Why can't the same be done with the latest/current release of macOS (and iOS/iPadOS)?
Because Safari is the new IE. I only somewhat kid... Remember when we all blasted Microsoft for this exact behavior in Win98? :(
Score: 13 Votes (Like | Disagree)
ian87w Avatar
37 months ago

Using Firefox while Safari is being repaired is a great idea ?
Not when you are on iOS. Every browsers on iOS use the same Safari/Webkit engine, and are affected by this bug.
Score: 12 Votes (Like | Disagree)