{"id":657830,"date":"2026-08-25T23:40:00","date_gmt":"2026-08-25T23:40:00","guid":{"rendered":"https:\/\/buglecall.org\/?p=657830"},"modified":"2026-08-25T23:40:00","modified_gmt":"2026-08-25T23:40:00","slug":"bluetooth-glitch-exposes-alibabas-secret-tracking-of-users-developer-says-3","status":"publish","type":"post","link":"https:\/\/buglecall.org\/?p=657830","title":{"rendered":"Bluetooth Glitch Exposes Alibaba&#8217;s Secret Tracking Of Users, Developer Says"},"content":{"rendered":"<p><span class=\"field field--name-title field--type-string field--label-hidden\">Bluetooth Glitch Exposes Alibaba&#8217;s Secret Tracking Of Users, Developer Says<\/span><\/p>\n<div class=\"clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item\">\n<p>A San Francisco-based developer <strong>discovered that Alibaba Group&#8217;s AliExpress marketplace secretly hijacked his computer&#8217;s audio system through hidden browser scripts<\/strong>, allowing the website to run inaudible sound waves at zero volume to create &#8220;fingerprints&#8221; used to track devices without relying on cookies.\u00a0<\/p>\n<p>The <a href=\"https:\/\/x.com\/brave\/status\/2091232672659972110\">privacy-focused Brave browser<\/a> revealed in a series of X posts that the AliExpress marketplace was keeping the developer&#8217;s computer audio system active through hidden browser scripts, <strong>potentially allowing the website to generate a unique identifier for his device.<\/strong><\/p>\n<p>The <strong>issue emerged when the developer&#8217;s Bluetooth headphones<\/strong> refused to transfer their audio connection from his computer to his phone while AliExpress was open. A deeper dive of the website&#8217;s code showed background scripts maintaining access to the computer&#8217;s audio-processing system without producing audible sound.<\/p>\n<p>The scripts <strong>allegedly used the browser&#8217;s Web Audio API to process signals at zero volume<\/strong>. Small differences in how individual computers handle those signals can be measured and combined into an &#8220;<strong>audio fingerprint<\/strong>,&#8221; allowing websites to recognize devices even when cookies are deleted or blocked.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\" xml:lang=\"en\">Alibaba&#8217;s AliExpress was caught using users&#8217; audio systems to track them.<\/p>\n<p>AliExpress wasn&#8217;t recording users but instead playing a silent sound and measuring how users&#8217; specific devices processed it in order to fingerprint them.<\/p>\n<p>But don&#8217;t worry because Brave stops this.<\/p>\n<p>\u2014 Brave (@brave) <a href=\"https:\/\/x.com\/brave\/status\/2091232672659972110?ref_src=twsrc%5Etfw\">August 22, 2026<\/a><\/p><\/blockquote>\n<p>The developer also found that the <strong>scripts collected other device characteristics, including available memory, screen dimensions, and network information<\/strong>.<\/p>\n<p><strong>Here&#8217;s what Brave found:<\/strong><\/p>\n<p><em>1. Alibaba&#8217;s AliExpress was caught using users&#8217; audio systems to track them. AliExpress wasn&#8217;t recording users but instead playing a silent sound and measuring how users&#8217; specific devices processed it in order to fingerprint them.<\/em><\/p>\n<p><em>2. Fingerprinting is a way that websites can identify you without cookies. Sites will note details about your device like your screen size or installed fonts. These details are then combined into a unique, persistent &#8220;fingerprint&#8221; that can be used to track you across the Web.<\/em><\/p>\n<p><em>3. There are slight variations in how each device plays the same audio file due to differences in CPU, sound card, browser, etc. When AliExpress played the silent sound, it measured these small variations to help build fingerprints of users&#8217; devices.<\/em><\/p>\n<p><em>4. This tracking was discovered due to an unexpected side effect. A user with Bluetooth headphones noticed they couldn&#8217;t play music on their phone because the headphones were instead playing AliExpress&#8217;s silent sound from their PC.<\/em><\/p>\n<p><strong>Brave turned what it found into a sales pitch for its browser:<\/strong><\/p>\n<p><em>1. For 6+ years, Brave has protected users against audio fingerprinting, and other fingerprinting types, by default. Brave injects random data into the browser&#8217;s output so you show a different fingerprint to different sites. This fingerprint also resets across sessions.<\/em><\/p>\n<p><em>2. Trackers are constantly finding new ways to fingerprint your device, so Brave keeps adding new protections. We recently added defenses against GPU fingerprinting, which stops sites from identifying you with your graphics card or drivers.<\/em><\/p>\n<p>The findings raise new questions about\u00a0browser fingerprinting, a stealthy way that uses silent audio processing for covert tracking.\u00a0<\/p>\n<\/div>\n<p>      <span class=\"field field--name-uid field--type-entity-reference field--label-hidden\"><a title=\"View user profile.\" href=\"https:\/\/cms.zerohedge.com\/users\/tyler-durden\" lang=\"\" class=\"username\" xml:lang=\"\">Tyler Durden<\/a><\/span><br \/>\n<span class=\"field field--name-created field--type-created field--label-hidden\">Tue, 08\/25\/2026 &#8211; 19:40<\/span><\/p>","protected":false},"excerpt":{"rendered":"<p>Bluetooth Glitch Exposes Alibaba&#8217;s Secret Tracking Of Users, Developer Says A San Francisco-based developer discovered that Alibaba Group&#8217;s AliExpress marketplace secretly hijacked his computer&#8217;s audio system through hidden browser scripts, allowing the website to run inaudible sound waves at zero volume to create &#8220;fingerprints&#8221; used to track devices without relying on cookies.\u00a0 The privacy-focused Brave&hellip; <a class=\"more-link\" href=\"https:\/\/buglecall.org\/?p=657830\">Continue reading <span class=\"screen-reader-text\">Bluetooth Glitch Exposes Alibaba&#8217;s Secret Tracking Of Users, Developer Says<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[20,23],"tags":[],"class_list":["post-657830","post","type-post","status-publish","format-standard","hentry","category-economic-empowerment","category-national-security","entry"],"_links":{"self":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/posts\/657830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=657830"}],"version-history":[{"count":0,"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/posts\/657830\/revisions"}],"wp:attachment":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=657830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=657830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=657830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}