Safari 15 Security Flaw Discovered That Can Leak Your Browsing Activity, Personal Identity

The Safari vulnerability was reported to the WebKit Bug Tracker in November, though Apple has not yet released its fix.

Advertisement
By Jagmeet Singh | Updated: 17 January 2022 18:51 IST
Highlights
  • Safari 15 is found to have poorly implemented IndexedDB API
  • It is leaking browsing activity and personal identity of users
  • iOS and iPadOS users couldn’t protect data even after switching browser
Safari 15 Security Flaw Discovered That Can Leak Your Browsing Activity, Personal Identity

Safari users on Mac are recommended to switch to a third-party browser

Safari 15 is found to have a vulnerability that is leaking your browsing activity and even allowing bad actors to know your identity. The issue has emerged due to a bug introduced in the implementation of IndexedDB, which works as an application programming interface (API) to store structured data. Users on the latest version of macOS as well as iOS and iPadOS are affected by the vulnerability. Although macOS users can overcome the impact by switching to a third-party browser, users with the iPhone or iPad have no such remedy at this moment.

As initially reported by 9to5Mac, browser fingerprint and fraud detection firm FingerprintJS has discovered the IndexedBD vulnerability impacting Safari 15. The API follows the same-origin policy that is meant to restrict documents and scripts loaded from one origin to be interacted with resources from other origins. This helps a Web browser secure your session in one tab from the website you have accessed on the other tab.

However, the researchers at FingerprintJS have found that Apple's implementation of IndexedDB violates the policy. This results in the loophole that an attacker can exploit to gain access to your browsing activity or identity attached to your Google account.

“Every time a website interacts with a database, a new (empty) database with the same name is created in all other active frames, tabs, and windows within the same browser session,” the researchers said while explaining the vulnerability.

The flaw allows hackers to learn what websites you are visiting in different tabs or windows. It also exposes your Google User ID to websites other than those where you have logged in with your Google account. The Google User ID allows websites to access your personal identifiers including your profile picture. Eventually, hackers could look at those identifiers by exploiting the Safari vulnerability.

Advertisement

FingerprintJS claims that the number of websites that can interact and gain access to users' browsing activity and personal identifiers can be significant. To demonstrate the flaw, a proof-of-concept has also been made public by the researchers.

You can use the demo on your Mac, iPhone, or iPad that has Safari 15 to look at the vulnerability. It currently detects popular sites including Alibaba, Instagram, Twitter, and Xbox to suggest how the database from one site can be leaked to others. However, the issue is not limited to these and may impact users visiting other sites as well.

Advertisement

Users switching to the private mode in Safari 15 can reduce the extent of information available via the leak as private browsing sessions on the browser are restricted to a single tab. You will, though, end up leaking your data if you visit multiple websites one after another within the same tab.

Mac users can, nevertheless, switch to a third-party browser, such as Google Chrome or Mozilla Firefox, to resolve the security loophole.

Advertisement

However, on iOS, the issue is also not just limited to Safari and cannot be overcome by moving to Chrome or another third-party browser. It is because Apple does not allow iOS Web browsers to use a third-party browser engine on iPhone and iPad.

Users can limit data leak by disabling JavaScript on their browser for the time being. But that will affect their experience as most sites nowadays use JavaScript to provide modern browsing.

FingerprintJS reported the issue to the WebKit Bug Tracker on November 28. The flaw still exists, though.

Gadgets 360 has reached out to Apple for a comment on the vulnerability and whether it is working on a fix. This article will be updated when the company responds.

Vulnerabilities impacting Safari is not something new. Last year, Apple had to re-release its browser to fix security issues and bugs that were introduced by a previous update. The latest Safari build (version 15.2) that was released in December also fixed six known WebKit security issues that existed in the previous versions and could allow attackers to maliciously gain user data access.


Xiaomi India speaks exclusively to Orbital, the Gadgets 360 podcast, on their plans for 2022 and pushing for 120W fast charging with the 11i HyperCharge. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Vivo X200 FE Compact Smartphone Launched With 6,500mAh Battery
  2. Kubera OTT Release Reportedly Revealed: Where to Watch Dhanush Starrer Movie Online?
  3. Nothing Phone 3a Pro 5G Long Term Review: A Blend of Style, Speed, and Power
  4. Oppo K13x 5G With 6,000mAh Battery Launched in India: See Price
  5. Tesla Set to Open India Showrooms in July With Made-in-China EVs
  6. Honor Magic V5 Thickness, RAM and Storage Details Teased Ahead of Launch
  7. AI+ Pulse, AI+ Nova 5G India Launch Timeline, Design and Colours Revealed
  8. 'Ghost' Plume Found Beneath Oman May Explain India's Ancient Tectonic Shift
  1. ‘Ghost’ Plume Found Beneath Oman May Explain India’s Ancient Tectonic Shift
  2. Blue Origin’s Crewed Suborbital Launch Delayed Again Due to Weather Conditions
  3. Green Rooftops Could Help Cities Like Shanghai Filter Out Tons of Microplastics from Rainwater
  4. SpaceX to Launch Over 150 Memorial DNA Capsules into Orbit on Celestis’ Perseverance Flight
  5. Rubin Observatory to Unveil First Cosmic Images with World’s Largest Digital Camera
  6. The Gilded Age OTT Release: Where to Watch This HBO Original Series
  7. Cleaner (2025) OTT Release Date: When and Where to Watch it Online?
  8. Yugi Now Available for Streaming on Aha Tamil: Everything You Need to Know
  9. Samsung Exynos 2500 SoC With Up to 15 Percent Improved CPU Performance, Xclipse 950 GPU Launched
  10. Vivo X200 FE With 6,500mAh Battery, MediaTek Dimensity 9300+ SoC Launched: Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.