Apple Prepares Fix for Safari Bug Allowing Websites to Decipher Your Recent Browsing Activity

Over the weekend, we reported on a bug in WebKit's implementation of a JavaScript API called IndexedDB that can reveal your recent browsing history and even your identity, according to browser fingerprinting service FingerprintJS.

safari icon blue banner
Apple has since prepared a fix for the bug, according to a WebKit commit on GitHub, but the fix will not be available to users until Apple releases macOS Monterey, iOS 15, and iPadOS 15 updates with an updated version of Safari. Apple declined to comment when asked to provide a timeframe for a fix being released to the public.

The bug allows any website that uses IndexedDB for client-side data storage to access the names of IndexedDB databases generated by other websites during a user's browsing session. The bug could allow one website to track other websites the user visits in different tabs or windows, as the database names are often specific to each website, and sometimes the database names contain user-specific identifiers that could reveal a user's identity.

FingerprintJS has a live demo of the bug, which affects newer versions of browsers using Apple's open source browser engine WebKit, including Safari 15 for macOS and Safari on all versions of iOS 15 and iPadOS 15. The bug also affects third-party browsers like Chrome and Edge on iOS 15 and iPadOS 15, as Apple requires all iPhone and iPad browsers to use WebKit.

The bug does not affect Safari 14 for macOS or any browser on iOS 14 and iPadOS 14, according to FingerprintJS, which has a blog post with more details.

Tag: Safari

Top Rated Comments

ouimetnick Avatar
12 months ago

but the fix will not be available to users until Apple releases macOS Monterey, iOS 15, and iPadOS 15 updates with an updated version of Safari.
Why can't we have Safari separated from the OS? I didn't have to update macOS for iTunes updates. Never had to update iOS for updates to Pages, Numbers, Keynote, etc.

They do update Safari separate from macOS on older versions of macOS.. Why can't the same be done with the latest/current release of macOS (and iOS/iPadOS)?
Score: 17 Votes (Like | Disagree)
TheYayAreaLiving ? Avatar
12 months ago

What do you mean Apple is preparing for a fix?

Apple just issued a fix for macOS and users can get it right here ('https://www.mozilla.org/en-US/firefox/new/') :p
I’m a big fan of Mozilla, Firefox browser. Been using it for years. Possibly a decade. It's too bad I'm addicted to Safari. But Firefox is my 2nd go-to.

Good suggestion though. ?☝️
Score: 14 Votes (Like | Disagree)
KaliYoni Avatar
12 months ago

The bug does not affect Safari 14 for macOS or any browser on iOS 14 and iPadOS 14
Yet again, upgrading right when a new macOS or iOS is released causes major problems for users! If I could get Tim Cook to do one thing, it would be to stop the forced annual releases of OS's. It's not like Apple would take a sales revenue hit from stretching out releases to 18 or 24 months...
Score: 13 Votes (Like | Disagree)
sw1tcher Avatar
12 months ago
What do you mean Apple is preparing for a fix?

Apple just issued a fix for macOS and users can get it right here ('https://www.mozilla.org/en-US/firefox/new/') :p
Score: 13 Votes (Like | Disagree)
diamondsw Avatar
12 months ago

Why can't we have Safari separated from the OS? I didn't have to update macOS for iTunes updates. Never had to update iOS for updates to Pages, Numbers, Keynote, etc.

They do update Safari separate from macOS on older versions of macOS.. Why can't the same be done with the latest/current release of macOS (and iOS/iPadOS)?
Because Safari is the new IE. I only somewhat kid... Remember when we all blasted Microsoft for this exact behavior in Win98? :(
Score: 13 Votes (Like | Disagree)
ian87w Avatar
12 months ago

Using Firefox while Safari is being repaired is a great idea ?
Not when you are on iOS. Every browsers on iOS use the same Safari/Webkit engine, and are affected by this bug.
Score: 12 Votes (Like | Disagree)

Related Stories

homekit showdown 2 thumb

iOS 15.2.1 and iPadOS 15.2.1 Address HomeKit Vulnerability

Wednesday January 12, 2022 10:31 am PST by
Apple today released iOS 15.2.1 and iPadOS 15.2.1, minor updates that include an important security fix for a known HomeKit vulnerability that was first discovered last year. According to Apple's security support document for the update, it addresses an issue that could cause a maliciously crafted HomeKit name to result in a denial of service, causing iPhones and iPads not to work. Apple...
ios 15

Apple Seeds iOS 15.3 and iPadOS 15.3 Release Candidates to Developers [Update: Public Beta Available]

Thursday January 20, 2022 10:13 am PST by
Apple today seeded the release candidate versions of upcoming iOS 15.3 and iPadOS 15.3 updates to developers for testing purposes, with the new software coming one week after the launch of the second betas and over a month after the launch of iOS 15.2 and iPadOS 15.2. iOS and iPadOS 15.3 can be downloaded through the Apple Developer Center or over the air after the proper profile has been...
Safari Technology Preview Feature

Apple Releases Safari Technology Preview 142 With Bug Fixes and Performance Improvements

Wednesday March 23, 2022 4:20 pm PDT by
Apple today released a new update for Safari Technology Preview, the experimental browser Apple first introduced in March 2016. Apple designed the Safari Technology Preview to test features that may be introduced into future release versions of Safari. Safari Technology Preview release 142 includes bug fixes and performance improvements for Web Inspector, CSS Subgrid, CSS Container Queries,...
safari icon blue banner

Apple Working on Safari Dark Mode Toggle for Viewing Specific Websites

Tuesday March 1, 2022 4:42 am PST by
Apple appears to be working on an upcoming Safari feature that will introduce a Dark mode user preference for individual websites, based on references found in open-source WebKit code. WebKit is Apple's browser engine that powers all browsers on iOS, and the new option, spotted by 9to5Mac, is referred in the GitHub-hosted WebKit code as "overriding the system color-scheme with a per-website...
iOS 15 General Feature Blue

Apple Releases iOS 15.3.1 and iPadOS 15.3.1 With Security Updates and Bug Fixes

Thursday February 10, 2022 10:10 am PST by
Apple today released iOS 15.3.1 and iPadOS 15.3.1, two minor updates to the iOS and iPadOS operating systems released in September 2021. iOS and iPadOS 15.3.1 come two weeks after the release of iOS and iPadOS 15.3. The iOS 15.3.1 and iPadOS 15.3.1 updates can be downloaded for free and the software is available on all eligible devices over-the-air in the Settings app. To access the new...
iOS 15

Apple Seeds Fourth Betas of iOS 15.4 and iPadOS 15.4 to Developers [Update: Public Beta Available]

Tuesday February 22, 2022 10:07 am PST by
Apple today seeded the fourth betas of upcoming iOS 15.4 and iPadOS 15.4 updates to developers for testing purposes, with the new software coming one week after Apple seeded the third betas of iOS 15.4 and iPadOS 15.4. Developers can download iOS 15.4 and iPadOS 15.4 through the Apple Developer Center or over the air after the proper profile has been installed on an iPhone or iPad. iOS...
safari icon blue banner

Safari Bug Allows Websites to Track Your Recent Browsing Activity in Real Time [Updated]

Sunday January 16, 2022 3:37 pm PST by
A bug in WebKit's implementation of a JavaScript API called IndexedDB can reveal your recent browsing history and even your identity, according to a blog post shared on Friday by browser fingerprinting service FingerprintJS. In a nutshell, the bug allows any website that uses IndexedDB to access the names of IndexedDB databases generated by other websites during a user's browsing session....
safari icon blue banner

Microsoft Edge Looks Set to Overtake Safari as World's Second Most Popular Desktop Browser

Tuesday February 22, 2022 6:48 am PST by
Microsoft Edge is on the verge of overtaking Safari as the world's second most popular desktop browser, web analytics service StatCounter reports (via TechRadar). According to the data, Microsoft Edge is now used on 9.54 percent of desktops worldwide, a mere 0.3 percent behind Apple's Safari, which stands at 9.84 percent. Google Chrome continues to hold first place with an overwhelming 65.38 ...

Popular Stories

Emergency SOS via Satellite iPhone YT

Apple's iPhone 14 Emergency SOS via Satellite Feature Saves Stranded Man in Alaska

Thursday December 1, 2022 4:37 pm PST by
With the launch of iOS 16.1, Apple rolled out a Emergency SOS via Satellite, which is designed to allow iPhone 14 owners to contact emergency services using satellite connectivity when no cellular or WiFi connection is available. The feature was put to the test in Alaska today, when a man became stranded in a rural area. In the early hours of the morning on December 1, Alaska State Troopers ...
General iOS 16 Feature Yellow

iOS 16.2 for iPhone Launching This Month With These 8 New Features

Thursday December 1, 2022 8:44 am PST by
Apple plans to publicly release iOS 16.2 for the iPhone in mid-December, according to Bloomberg's Mark Gurman. The update remains in beta testing for now, with at least eight new features and changes already uncovered so far. iOS 16.2 introduces a number of new features, including Apple's new whiteboard app Freeform, two new Lock Screen widgets for Sleep and Medications, the ability to hide...
iOS 16

Apple Releases iOS 16.1.2 With Carrier Improvements and Crash Detection Optimizations

Wednesday November 30, 2022 10:09 am PST by
Apple today released iOS 16.1.2, another minor bug fix update that comes one week after the release of iOS 16.1.1 and three weeks after the launch of iOS 16.1, an update that added support for iCloud Shared Photo Library, Matter, Live Activities, and more. The iOS 16.1.2 update can be downloaded on eligible iPhones over-the-air by going to Settings > General > Software Update. According...
iPad 10 Battery Pull Tabs

iPad 10 Teardown Reveals Why Device Isn't Compatible With Apple Pencil 2

Thursday December 1, 2022 10:48 am PST by
Do-it-yourself repair website iFixit today shared a video teardown of Apple's new 10th-generation iPad, providing a closer look inside the tablet and revealing why the device lacks support for the second-generation Apple Pencil. The teardown reveals the internal layout of the iPad, including its two-cell 7,606 mAh battery, logic board with the A14 Bionic chip, and more. As suspected, the...
iOS 16

When Will iOS 16.2 Be Released?

Friday December 2, 2022 2:13 pm PST by
Apple in late October began testing iOS 16.2 and iPadOS 16.2 updates, providing betas to both developers and public beta testers. As of now, we've had four total betas, with the fourth beta having been released earlier this week. iOS 16.2 and iPadOS 16.2 are expected before the end of the year, and we thought we'd try to narrow down the launch timeline. With only four betas released since...
14 vs 16 inch mbp m2 pro and max feature 1

Major RAM Upgrade Coming to Next-Generation MacBook Pro

Friday December 2, 2022 2:03 am PST by
The next-generation MacBook Pro models could feature faster RAM, according to a recent report from a reliable source. MacRumors Forums member "Amethyst," who accurately revealed details about the Mac Studio and Studio Display before those products were announced, recently provided information about Apple's upcoming 14- and 16-inch MacBook Pro models. The new machines are expected to feature...
iOS 16

Apple Still Has These 5 Things to Release Heading Into 2023

Thursday December 1, 2022 7:12 am PST by
The calendar has turned to December and that means Apple has only one month left to fulfill its promises of releasing an Apple Music Classical app and expanding its self-service repair program to Europe before the end of 2022. Delays are always possible, of course, so the plans could be pushed back to 2023. In any case, we have put together a list of five things that Apple still has to release...
iOS 16

Apple Seeds Fourth Betas of iOS 16.2 and iPadOS 16.2 [Update: Public Beta Available]

Thursday December 1, 2022 10:16 am PST by
Apple today seeded the fourth betas of upcoming iOS 16.2 and iPadOS 16.2 updates to developers for testing purposes, with the betas coming two weeks after Apple seeded the third betas of iOS 16.2 and iPadOS 16.2. Registered developers are able to download the iOS 16‌.2 and iPadOS 16.2 profiles from the Apple Developer Center, and once installed, the beta is available over the air. iOS...
iPhone Measure Height

Newer iPhones Allow You to Measure Someone's Height Instantly — Here's How

Saturday December 3, 2022 10:23 am PST by
iPhone 12 Pro and Pro Max, iPhone 13 Pro and Pro Max, and iPhone 14 Pro and Pro Max models feature a LiDAR Scanner next to the rear camera that can be used to measure a person's height instantly in Apple's preinstalled Measure app. To measure a person's height, simply open the Measure app, point your iPhone at the person you want to measure, and make sure they are visible on the screen from...
apple ar headset concept 2

Apple Now Calling AR/VR Headset Operating System 'xrOS'

Thursday December 1, 2022 12:57 pm PST by
Apple has decided to call the software that will run on its upcoming AR/VR headset "xrOS," an update from the original "RealityOS or "rOS" naming the company was planning on, according to Bloomberg. Render created by Ian Zelbo based on rumored information The name change comes as Apple begins to prepare for the launch of the headset, which is expected at some point in 2023. The headset will...