AliExpress Audio Fingerprinting Hijacks Your Bluetooth

AliExpress Audio Fingerprinting Hijacks Your Bluetooth
AliExpress was found silently running WebAudio-based fingerprinting scripts in the browser, which even interfered with a researcher’s Bluetooth multipoint headphones while appearing to play no visible media. The hidden tracking code, tied to Alibaba’s AWSC anti-abuse tooling, also collected canvas, WebGL, hardware, and user interaction data for telemetry and fraud detection. #AliExpress #Alibaba #AWSC #Laserphile

Keypoints

  • AliExpress quietly triggered hidden WebAudio activity in the browser.
  • The issue caused audio on a connected phone to stop when the page loaded.
  • Two obfuscated scripts, collina.js and fireyejs.js, built muted audio graphs.
  • The scripts also collected canvas, WebGL, screen, and hardware data.
  • uBlock Origin filters can block the scripts, but may increase CAPTCHAs.

Read More: https://securityonline.info/aliexpress-audio-fingerprinting/