<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Apple Safari Archives - Gizmochina</title>
	<atom:link href="https://www.gizmochina.com/tag/apple-safari/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.gizmochina.com/tag/apple-safari/</link>
	<description>Latest Tech News, Product Reviews and Deals</description>
	<lastBuildDate>Mon, 17 Jan 2022 13:06:10 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.9</generator>
	<item>
		<title>Safari bug lets nefarious sites scoop your browsing history and Google account info</title>
		<link>https://www.gizmochina.com/2022/01/17/safari-bug-lets-nefarious-sites-scoop-browsing-history-google-account-info/</link>
		
		<dc:creator><![CDATA[Zohaib Ahmed]]></dc:creator>
		<pubDate>Mon, 17 Jan 2022 13:06:10 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Apple Safari]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[Javascript IndexedDB]]></category>
		<category><![CDATA[Safari browser]]></category>
		<category><![CDATA[Safari IndexedDB vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=437983</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-300x169.png?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="apple safari featured" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-747x420.png 747w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured.png 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>A bug in Safari found by security company FingerprintJS (via 9to5Mac) can let any website track your browsing history and even some information pertaining to the logged-in Google account. It is present in Safari&#8217;s IndexedDB implementation on Mac and iOS and lets websites see names of databases for any domain and not just its own. [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/01/17/safari-bug-lets-nefarious-sites-scoop-browsing-history-google-account-info/">Safari bug lets nefarious sites scoop your browsing history and Google account info</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-300x169.png?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="apple safari featured" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-747x420.png 747w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured.png 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>A bug in Safari found by security company <a href="https://fingerprintjs.com/blog/indexeddb-api-browser-vulnerability-safari-15/">FingerprintJS</a> (via <a href="https://9to5mac.com/2022/01/16/safari-bug-leak-browsing-history-info/">9to5Mac</a>) can let any website track your browsing history and even some information pertaining to the logged-in Google account.</p>
<p>It is present in Safari&#8217;s IndexedDB implementation on Mac and iOS and lets websites see names of databases for any domain and not just its own. IndexedDB is a Javascript API that according to the report holds &#8220;a significant amount of data.&#8221;</p>
<p><img loading="lazy" class="size-large wp-image-438000 aligncenter" src="https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-1024x576.png?x10805" alt="apple safari featured" width="696" height="392" srcset="https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured-747x420.png 747w, https://www.gizmochina.com/wp-content/uploads/2022/01/apple-safari-featured.png 1920w" sizes="(max-width: 696px) 100vw, 696px" /></p>
<p>These database names can then be used to extract identifying information from a lookup table. <a href="http://gizmochina.com/tag/Google">Google</a> services, for example, store an IndexedDB instance for each of your logged-in accounts. This can be accessed by malicious sites to unearth other information about you, such as your Google account profile picture.</p>
<p>While the <a href="https://safarileaks.com/">proof-of-concept demo</a> by FingerprintJS only keeps an index of about 30 sites, there&#8217;s quite a chance of the exploit being applied to a much larger set. Almost every site that uses the IndexedDB JavaScript API could be vulnerable to such data scraping.</p>
<p>Unfortunately, there isn&#8217;t much that can be done from the user&#8217;s end to fix the Safari bug other than blocking Javascript completely on untrusted sites, which isn&#8217;t too feasible as doing so will likely be breaking stuff on web pages.</p>
<p>The only proper fix can obviously be applied by <a href="http://gizmochina.com/tag/Apple">Apple</a> alone. Browsers like Chrome only let websites access databases on IndexedDB created by the same domain name as their own, and it&#8217;s time Apple heads the same way with Safari.</p>
<p>FingerprintJS says that it has already reported the bug to Apple on November 28 but a fix still remains to be seen.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2022/01/17/aqara-smart-door-lock-a100-pro-launched-with-apple-home-key-support/">Aqara Smart Door Lock A100 Pro launched with Apple Home Key support</a></li>
<li><a href="https://www.gizmochina.com/2022/01/17/powerbeats-pro-false-battery-claims-land-apple-in-a-bit-of-legal-trouble/">Alleged false battery life claims on Powerbeats Pro land Apple in a bit of legal trouble</a></li>
<li><a href="https://www.gizmochina.com/2022/01/14/pubg-maker-sues-apple-google-garena-free-fire/">PUBG maker is suing Apple, Google, &amp;amp; Free Fire developer Garena</a></li>
<li><a href="https://www.gizmochina.com/2022/01/13/apple-iphone-14-pro-again-tipped-feature-48mp-main-camera/">Apple&#8217;s upcoming iPhone 14 Pro again tipped to feature a 48MP main camera</a></li>
<li><a href="https://www.gizmochina.com/2022/01/13/apple-iphones-are-the-most-sold-phones-in-china-for-6th-consecutive-week/">Apple iPhones are the most sold phones in China for 6th consecutive week</a></li>
</ul>
<p><iframe loading="lazy" title="Realme GT 2 Pro Review: Realme Flagship Virgin" width="696" height="392" src="https://www.youtube.com/embed/ZFFU33BfUd4?start=394&#038;feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<div class="notranslate" data-darkreader-inline-bgcolor="" data-darkreader-inline-bgimage="" data-darkreader-inline-border-top="" data-darkreader-inline-border-right="" data-darkreader-inline-border-bottom="" data-darkreader-inline-border-left="" data-darkreader-inline-boxshadow="" data-darkreader-inline-fill="" data-darkreader-inline-stroke="" data-darkreader-inline-color="" data-darkreader-inline-outline="" data-darkreader-inline-stopcolor=""></div>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/01/17/safari-bug-lets-nefarious-sites-scoop-browsing-history-google-account-info/">Safari bug lets nefarious sites scoop your browsing history and Google account info</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 32/37 objects using Redis
Page Caching using Disk: Enhanced 
Content Delivery Network Full Site Delivery via cloudflare
Database Caching 15/22 queries in 0.006 seconds using Redis
Fragment Caching 2/3 fragments using Redis

Served from: www.gizmochina.com @ 2026-04-19 16:31:12 by W3 Total Cache
-->