AliExpress caught using inaudible audio to fingerprint browsers

AliExpress caught using inaudible audio to fingerprint browsers

AliExpress was caught playing inaudible high-frequency audio to fingerprint visitor browsers and track users across devices.

According to a report by Ars Technica, the online retailer used an outdated web audio trick that relies on how different hardware and operating systems process browser sound. Security researcher Callaghan discovered the audio technique alongside more than a dozen other fingerprinting methods active on the site, including canvas rendering, WebGL output, installed plugins, device memory, and screen dimensions.

Why it matters: Your browser likely defanged this specific audio hack years ago. Firefox fixed it in 2023 by bundling its own constant math libraries, Chrome ships with its own libraries to neutralize the trick, and Safari users are likely safe for the same reason. The catch? AliExpress is still firing off over a dozen other tracking metrics, and thousands of other sites are using similar tactics to identify users across the web.

Know this: Researchers suspect the audio trick is a legacy artifact left over from years past that no one bothered to clean up. Browser developers and site publishers remain in a continuous race as trackers look for new browser quirks to bypass modern privacy protections.

Proof that even after a web tracking trick stops working, the legacy code trying it lives on.