apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
apple patient
No Result
View All Result

Safari bug can reveal some Google account data and more

by Milan
January 16, 2022
Safari Security

Paris, France - Oct 20, 2021: Safari internet browser new features settings suggestions and icons on new Apple Computers iPad mini tablet during first run

A serious Safari bug uncovered by FingerprintJS can reveal information about the current browsing history and even some data from the logged-in Google account.

A bug in Safari's IndexedDB implementation on Mac and iOS means that a website can see the names of databases for any domain, not just its own. The database names can then be used to extract identifying information from a lookup table, FingerprintJS reports in a new Contribution. For example, Google services store an IndexedDB instance for each of your logged-in accounts, where the name of the database corresponds to your Google User ID. With the exploit described in the post, a malicious website could read your Google User ID and then use that ID to find out other personal information about you, since the ID is used to make API requests to Google services. The proof-of-concept demo shows the user's profile picture.

Safari bug: Apple has not yet responded

The proof of concept only contains a lookup table with about 30 domain names, but there's no reason why the technique can't be applied to a much larger set. Almost any website that uses the IndexedDB JavaScript API could be vulnerable to such data scraping. The flaw is simply that the names of all IndexedDB databases are accessible to any website, but access to the actual contents of each database is restricted. The solution - and the correct behavior observed in other browsers like Chrome - is that a website can only see the databases created under the same domain name as its own. All current versions of Safari on iPhone, iPad and Mac are affected. FingerprintJS says they reported the bug to Apple on November 28, but the problem has not yet been fixed. (Photo by hadrian / Bigstockphoto)

  • iOS 15: How to use the native iPhone 2FA code generator
Have you already visited our Amazon Storefront? There you'll find a hand-picked selection of various products for your iPhone and other devices – enjoy browsing !
This post contains affiliate links .
Add Apfelpatient to your Google News Feed. 
Was this article helpful?
YesNo
Tags: Apple servicesiOSiPadOSmacOSsafari
Previous Post

iPhone 14: ProMotion will probably remain a Pro feature

Next Post

iPhone SE+ 5G: Successor to the iPhone SE 3 to have a larger display

Next Post
iPhone SE+ 5G

iPhone SE+ 5G: Successor to the iPhone SE 3 to have a larger display

Apple TV+ highlights August 2025

Apple TV+: These are the highlights for August 2025

August 1, 2025
Apple iPhone

Apple sells three billionth iPhone since 2007

August 1, 2025
Apple tariffs

Apple faces record tariff costs in Q4

July 31, 2025

About APFELPATIENT

Welcome to your ultimate source for everything Apple - from the latest hardware like iPhone, iPad, Apple Watch, Mac, AirTags, HomePods, AirPods to the groundbreaking Apple Vision Pro and high-quality accessories. Dive deep into the world of Apple software with the latest updates and features for iOS, iPadOS, tvOS, watchOS, macOS and visionOS. In addition to comprehensive tips and tricks, we offer you the hottest rumors, the latest news and much more to keep you up to date. Selected gaming topics also find their place with us, always with a focus on how they enrich the Apple experience. Your interest in Apple and related technology is served here with plenty of expert knowledge and passion.

Legal

  • Imprint – About APFEPATIENT
  • Cookie Settings
  • Privacy Policy
  • Terms of Use

service

  • Partner Program
  • Netiquette – About APPLEPATIENT

RSS Feed

Follow Apfelpatient:
Facebook Instagram YouTube threads
Apfelpatient Logo

© 2025 Apfelpatient. All rights reserved. | Sitemap

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally

© 2025 Apfelpatient. All rights reserved. | Page Directory