Researchers and developer Matt Callaghan reported that AliExpress used silent browser audio processing to fingerprint visitors, generating and analyzing sound data through the Web Audio API while keeping output inaudible by setting gain to zero. The code reportedly built a device profile by measuring hardware-specific audio differences and combining them with other signals including canvas, WebGL, display, hardware, WebRTC, and user interaction data, allowing persistent identification without relying on cookies. Callaghan said the issue was reproducible in Firefox and Chrome, and that he traced it to heavily obfuscated Alibaba anti-abuse scripts that created a WebAudio graph with a sawtooth oscillator, analyzer, and frequency-data reader.
The activity came to light after Callaghan noticed that an open AliExpress tab interfered with multipoint Bluetooth headphones, effectively muting audio on his devices. Browser vendors said existing protections reduce the impact: Brave said it blocks the AliExpress scripts and has long shipped defenses against audio and GPU-based fingerprinting, while Firefox said anti-fingerprinting protections added in version 118 largely neutralize WebAudio fingerprinting by placing users into a limited set of buckets. AliExpress had not publicly explained the purpose or scope of the tracking, though the scripts were linked to Alibaba security systems, suggesting possible fraud-prevention or bot-detection functions alongside user tracking.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
In a post on X, Brave said its browser blocks the AliExpress scripts responsible for audio-based tracking and noted it has long shipped protections against audio fingerprinting and related fingerprinting methods.
Firefox version 118 introduced protections designed to largely eliminate the effectiveness of WebAudio fingerprinting by grouping users into a small number of hardware-based buckets. Tom Ritter described the feature as making most users look the same to this technique rather than blocking script execution outright.
A Google spokesperson said the audio soundprinting technique is ineffective in Chrome because the browser ships with its own libraries rather than relying on OS-provided ones. The Ars Technica report presented this as a browser-vendor response to the AliExpress audio fingerprinting findings.
Firefox responded that its anti-fingerprinting protections neutralize the AliExpress WebAudio fingerprinting approach by making most users appear the same, rather than blocking the attempt outright.
Callaghan found heavily obfuscated scripts in Alibaba anti-abuse tooling that created a silent WebAudio processing graph and measured device-specific audio characteristics. He also observed collection of other browser and device signals, indicating a broader fingerprinting and telemetry system.
Developer Matt Callaghan noticed that opening an AliExpress page interfered with multipoint Bluetooth headphones, and that closing the tab restored normal behavior. This observation led him to investigate the site's browser audio activity.
Firefox security engineer Tom Ritter said Firefox version 118 introduced protections that largely eliminate the effectiveness of WebAudio-based fingerprinting by grouping most users into a small number of hardware-based buckets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
13 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetomshardware.com
Open sourcexakep.ru
Open sourcescworld.com
Open sourceghacks.net
Open sourcetechjuice.pk
Open sourceritter.vg
Open sourceblog.laserphile.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.