Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AliExpress Employs WebAudio for Device Fingerprinting

AliExpress Employs WebAudio for Device Fingerprinting

Posted on August 25, 2026 By CWS

AliExpress has implemented a sophisticated device fingerprinting mechanism using the WebAudio API, which has led to unexpected Bluetooth connectivity issues. This technique discreetly constructs WebAudio processing graphs in users’ browsers, potentially hindering Bluetooth multipoint audio switching for connected headphones.

Bluetooth Connectivity Disruptions

Security expert Laserphile discovered the issue while using multipoint Bluetooth headphones connected to both a PC and a phone. Opening the AliExpress homepage in browsers like Firefox or Chrome resulted in abrupt audio cutoffs from the phone. Standard methods such as muting the browser or the system audio were ineffective, and only closing the AliExpress tab restored normal audio playback.

Despite the absence of visible media content on the page, further investigation revealed two AudioContext instances being created. These instances were actively connected to the system’s audio destination, albeit producing no audible sound. The activity was traced back to scripts named collina.js and fireyejs.js, which are linked to Alibaba’s anti-fraud and bot detection systems.

Technical Investigation and Findings

Laserphile utilized advanced JavaScript instrumentation to monitor the WebAudio API, uncovering a complex audio graph pattern. This graph involved a sawtooth oscillator connected to an analyzer node and script processor, which then passed through a zero-gain node. Despite the absence of sound, this setup kept the audio processing active, leading Firefox and Windows to treat it as legitimate audio, thus maintaining the Bluetooth connection to the PC.

Beyond audio fingerprinting, these scripts assess various browser and device parameters, including canvas rendering, WebGL details, and hardware specifications. The collected data is encrypted and sent to Alibaba’s telemetry servers, possibly for fraud prevention and user behavior analysis.

Broader Implications and Mitigation

The fingerprinting occurs on the AliExpress homepage, without user consent or visible indicators, raising privacy concerns. A related Firefox bug report and analysis from a Mozilla engineer have confirmed parts of the behavior.

To mitigate these issues, Laserphile suggests using ad blockers like uBlock Origin to block the script paths, which prevents the hidden audio contexts from initiating and restores normal Bluetooth functionality. However, users may encounter additional CAPTCHA challenges as a result, since these scripts are integral to AliExpress’s fraud detection system.

As online platforms increasingly employ sophisticated tracking technologies, users and developers must remain vigilant about potential privacy implications and technical disruptions.

Cyber Security News Tags:AliExpress, AliExpress scripts, anti-fraud, audio graph, Bluetooth, browser behavior, device fingerprinting, digital security, JavaScript, online privacy, Security, tech news, user tracking, WebAudio API, WebAudio processing

Post navigation

Previous Post: WhatsApp Enhances Security: 1 Billion Use Passkeys

Related Posts

Renting Android Malware With 2FA Interception, AV Bypass is Getting Cheaper Now Renting Android Malware With 2FA Interception, AV Bypass is Getting Cheaper Now Cyber Security News
Critical HIKVISION ApplyCT Vulnerability Exposes Devices to Code Execution Attacks Critical HIKVISION ApplyCT Vulnerability Exposes Devices to Code Execution Attacks Cyber Security News
ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen ClickFix Attack Uses Steganography to Hide Malicious Code in Fake Windows Security Update Screen Cyber Security News
Hugging Face Exploited in North Korean Malware Attack Hugging Face Exploited in North Korean Malware Attack Cyber Security News
New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access Cyber Security News
New Report Warns of 68% Of Actively Serving Phishing Kits Protected by CloudFlare New Report Warns of 68% Of Actively Serving Phishing Kits Protected by CloudFlare Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AliExpress Employs WebAudio for Device Fingerprinting
  • WhatsApp Enhances Security: 1 Billion Use Passkeys
  • AI-Driven Botnet ToxNetV2 Targets Linux Systems
  • AI Redefines Vulnerability Management in Cybersecurity
  • Microsoft Teams Exploited in SynkLoader Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AliExpress Employs WebAudio for Device Fingerprinting
  • WhatsApp Enhances Security: 1 Billion Use Passkeys
  • AI-Driven Botnet ToxNetV2 Targets Linux Systems
  • AI Redefines Vulnerability Management in Cybersecurity
  • Microsoft Teams Exploited in SynkLoader Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark