AliExpress site uses silent audio to fingerprint users, disrupting Bluetooth headphones
Developer Matt Callaghan discovered that AliExpress runs hidden WebAudio scripts that generate inaudible sound to collect device fingerprints, which also caused his Bluetooth headphones to mute.
Matt Callaghan reported that visiting AliExpress triggers hidden WebAudio code that emits a silent sawtooth wave, captures frequency data, and transmits a comprehensive browser and device fingerprint to Alibaba’s servers. The audio graph runs at zero gain, so users hear nothing, yet the processing interferes with the Bluetooth multipoint switching on his headphones, cutting off audio from his phone. Callaghan found additional scripts gathering screen size, memory, plugins, WebGL and mouse events, all encrypted before being sent out.
Firefox and Brave say their anti-fingerprinting features neutralize the method, while Safari injects audio errors and Chrome currently lacks comparable defenses. The Register has sought comment from Alibaba, and security engineers note that only a tiny fraction of users remain uniquely identifiable by this approach.
Why it matters
It reveals a covert tracking method that can affect user privacy and device behavior across popular browsers.
In this story
