Skip to content
Safety · Aug 25, 2026

Researchers find AliExpress using outdated audio fingerprinting to track visitors

Outdated technique measured inaudible sounds to create unique browser signatures, but browser fixes have largely neutralized it.

Trust79
HypeLow hype

1 source · cross-referenced

ShareXLinkedInEmail
TL;DR
  • AliExpress embedded scripts that measured inaudible audio signals to fingerprint browsers, a technique mitigated by browser makers years ago.
  • Firefox disabled the fingerprinting vector starting in version 118 (2023) by standardizing math libraries.
  • Researcher discovered the tracking after his Bluetooth headphones repeatedly cut out while using AliExpress.
  • The site also employed at least a dozen other fingerprinting methods, including canvas rendering and WebGL data extraction.

A researcher discovered AliExpress using an outdated audio-based browser fingerprinting technique that measures inaudible sounds sent to browsers, a method browser vendors largely neutralized years ago. Matthew Callaghan found the tracking after his Bluetooth headphones repeatedly stopped playing audio from his phone whenever he loaded the AliExpress homepage, resuming only when he closed the tab. He traced the behavior to two obfuscated scripts that created an oscillator to measure Sawtooth waves in the browser’s audio output, sending frequency data back to AliExpress while preventing users from hearing anything.

Browser vendors have already addressed this specific fingerprinting vector. Firefox disabled it starting in version 118, released in 2023, by using its own constant math libraries instead of OS-provided ones, reducing entropy enough to make the technique ineffective. Chrome and Safari also rely on their own libraries, mitigating the technique in those browsers, according to a Google spokesperson and industry context provided in the report.

While the audio fingerprinting method is obsolete, AliExpress also employed at least a dozen other tracking techniques, including canvas rendering and toDataURL() extraction, WebGL renderer information, extension detection, shader precision metrics, screen and viewport dimensions, device pixel ratio, hardware concurrency and memory, installed plugins, supported audio and video formats, WebRTC behavior, performance timing, mouse and scroll events, device motion and orientation properties, and automation-related signals.

The persistence of this outdated technique in production suggests it may have been legacy code that went unnoticed until externally audited. Browser developers continue to update defenses as websites experiment with new tracking vectors, but the discovery indicates that many sites likely still employ similar, now-mitigated techniques.

Sources
  1. 01Ars Technica — Technology LabInaudible sounds used to fingerprint browsers catch AliExpress red-handed
Also on Safety

Stories may contain errors. Dispatch is assembled with AI assistance and curated by human editors; despite the trust-score filter, mistakes happen. We correct publicly — every article links to its revision history. Nothing here is financial, legal, or medical advice. Verify before relying on any claim.

© 2026 Dispatch. No ads. No sponsorships. No paid placement. Reader-supported via Ko-fi.

Built by a person who cares about honest AI news.