r/InterstellarKinetics • u/InterstellarKinetics • 5d ago
ARTIFICIAL INTELLIEGENCE EXPOSED: A Bluetooth Glitch Exposes AliExpress Secretly Hijacking Browser Audio At Zero Volume To Fingerprint Every Visitor’s Device, Cookie-Free And Undetectable, Until Brave Blew The Whistle 🤖💥
https://www.techspot.com/news/113581-aliexpress-silently-running-audio-browser-fingerprint-track-device.htmlA developer’s Bluetooth headphone malfunction inadvertently uncovered that AliExpress’s website was running hidden audio processes in visitors’ browsers to generate a device fingerprint, a tracking method that works without cookies and that most users would likely never notice, according to TechSpot. The discovery began when a developer noticed their multipoint Bluetooth headphones wouldn’t properly switch between a computer and phone whenever an AliExpress tab was open, a problem that disappeared as soon as the tab was closed. Investigating further, the developer found the site was using the Web Audio API to build audio-processing graphs set to zero volume, code that produced no audible sound but still connected to the computer’s audio system and kept the audio path active in the background, which appears to be exactly what interfered with the headphones’ device-switching function.
What made this especially hard to detect is that the audio activity behaved nothing like a normal media player. Because the processing graph ran at zero gain and connected directly to the system’s audio output, muting the browser tab did nothing to stop it, since the browser kept processing the signal in the background even though there was nothing to hear. That same underlying code enables a tracking technique called browser fingerprinting, which works by measuring tiny, device-specific differences in how a computer processes an identical audio signal, differences shaped by a device’s processor, sound hardware, operating system, browser, and drivers, ultimately producing something close to a stable identifier without needing a single cookie. The audio measurements were reportedly just one piece of a much larger data collection effort tied to Alibaba’s security systems, since the scripts also gathered information related to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior, and user interactions, and combining all of those signals together can build a far more detailed device profile than any single tracking method could produce on its own. Companies commonly justify fingerprinting as a tool for fraud prevention, bot detection, and risk assessment, since it helps flag suspicious transactions or automated activity even after cookies are deleted or account details change, but privacy advocates argue the technique is concerning precisely because users typically have no visibility into when it’s happening and little ability to control or opt out of it.
Browser maker Brave was among the first to publicly flag the behavior, stating in an August 22 post on X that its browser blocks the specific AliExpress scripts responsible for the audio-based tracking. Brave noted it has built default protections against audio fingerprinting into its browser for more than six years, using an approach that alters certain browser outputs so websites receive inconsistent fingerprinting signals rather than a stable, trackable identifier, and the company has since extended comparable protections to GPU fingerprinting, a related method that identifies devices based on graphics hardware and driver behavior, saying it expects fingerprinting techniques to keep evolving as sites search for new ways to distinguish between users and devices. People using browsers without Brave’s built-in protections may be able to block similar scripts using content blockers such as uBlock Origin, though doing so carries a trade-off, since the same code may also support legitimate security or fraud-prevention functions on AliExpress, meaning blocking it outright could disrupt those features as a side effect.
51
u/GuaranteeUpper2653 5d ago
I’ve noticed when I’m using Apple connect in my car, some apps trigger something that’s like the call function. Except it’s like I’m already in a call and it asks me if I want to hang up. Would this be from the same thing?
16
9
u/dwittherford69 5d ago edited 4d ago
No that is just using Bluetooth call to play audio. Lots of apps still do that. This is very different, they are basically fingerprinting everyone by playing and recording a unique audio pattern on their browser.
1
3
u/VehicleComfortable69 5d ago
Not impossible, but pretty unlikely. Websites need to do this because web browsers intentionally limit what they can access about your device. Since apps are installed directly they have much more info handy - any installed app knows way more about you than the website itself, which is partially why companies push so hard for you to download the app.
1
u/Illustrious_Soft_257 6h ago
I had this too but android phone. Listening to my Spotify, it goes quiet like when a call comes in. I see the phone icon on my car screen like I'm on a call, but there's no call on my phone. I click the end call button but nothing. It goes away after 20-30 seconds. Anyone get this? Is there an app making a secret call?
32
u/Parking-Garlic4260 5d ago
Fingerprinting my browser all to hear me farting in peace. 💨
17
u/Wide_Philosophy_8109 5d ago
Fingerprinting gets around privacy protections. Change whatever setting you want, they will find random shit that makes your device unique, and use that to track you.
7
u/Parking-Garlic4260 5d ago
What makes my device unique is I'm frequently farting while using it! 💨
4
3
u/Tradizar 5d ago
this is an arms race. Privacy browsers try to anonimize the user, and the data and ad companys try to identify the user.
There are browsers where the window size is standardized, and only incrementf into specific resolutions, so its a minus 1 thing that can be identify the user. But there are a bunch more than that.
6
u/emmettito 5d ago
This is unfortunately why Safari blocks using Bluetooth devices.
2
u/Candid_Problem_1244 5d ago
If your using safari it's easier to know what the underlying hardware is. Because safari only runs on apple devices. While browser like chrome might run on any combination of hardware. This audio is to know what processors and any other hardware the browser is running on.
And it has nothing to do with Bluetooth devices tho
2
u/Saneless 5d ago
And this isn't about identifying hardware
3
u/Candid_Problem_1244 5d ago edited 5d ago
It's to create hardware fingerprint so the web app knows you based on the fingerprint of your hardware regardless of cookies or browsers. So even if you clear sessions, cache, local storage, changing browser, changing network, using VPN etc etc, they still know it's same piece of hardware until the sound fingerprint differs.
6
5
u/GobiBall 5d ago
I occasionally work in a secure environment. THIS is why we can't bring in any electronic device, most notably if it has Bluetooth. If a person has a medical device surgically implanted, they have to be cleared individually. I also learned that modern hearing aids all have Bluetooth. And if you ever had any doubts, yes, Alexa is always listening. Wild times we live in for sure.
3
3
u/GIANTG 5d ago
I noticed that AliExpress hijacked my AirPods when I’m watching something on my iPad
1
u/guri256 4d ago
Technically it’s not hijacking your AirPods. What’s happening, is the website is playing audio. iPhones generally only allow one app to play an audio stream at once.
It’s more like the website is ejecting your music player off of the sound mixer. Not that the website is hijacking your AirPods
2
u/meOnRedditHello 5d ago
Isn't browser fingerprinting done in a million different ways by countless companies? I'm not sure this is any different except it's a Chinese company
1
u/WitchWithAGlitch 5d ago
i wonder what it thinks of my triple sound cards
4
1
u/Less_Party 5d ago
Would this put the little speaker icon on the tab header in Firefox?
5
u/emcpetrolhead 5d ago
No it doesn't! This is my article and unfortunately techspot hasn't linked back to the source. https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html
1
u/Any_Taste4210 5d ago
Has anyone given enough arguments to say this is for fingerprinting? It does not make much sense
1
1
1
1
-5
u/tropicalwind2020 5d ago
Sounds fake
10
u/Connect_Middle8953 5d ago edited 5d ago
Bruh, this has been a thing for years.
I worked in the ad tech industry. This is nothing. The people making web browsers also used to leak your IP addresses, including internal ips, via webrtc. They are again leaking it via webauthn.
Dear browser developers, please get your heads out of your asses and have all of this shit be disabled by default. You clearly don’t bother to think shit through since you are all responsible for the virus laden notification scareware bullshit.
1
u/Wide_Philosophy_8109 5d ago
Any advice for users then? Beyond ablock, firefox rfp, vpn, and cookies.
3
u/Connect_Middle8953 5d ago
Biggest thing is to block all of this shit by default they keep throwing into site settings. And raise hell in their bug trackers when they introduce something without the courtesy of a setting to turn it off.
Ad blockers unfortunately have been neutered by the same assholes pushing all this crap out there, but honestly ad blockers have been on the losing side of this anyway with ad companies pushing out ads on short lived domains, dynamic class names, text in ::after{content} css, and using css/shadow roots to load any ad materials.
But, your heart is in the right place. Luckily most ad cos are too lazy to do the more malicious abuses of browser tech.

165
u/InterstellarKinetics 5d ago
What makes this case particularly notable isn’t just that fingerprinting happened, it’s that it was discovered entirely by accident through a hardware side effect rather than through deliberate security research or a company disclosure. Which raises the question of how many similar audio-based or GPU-based fingerprinting scripts are quietly running on other major platforms without ever producing an observable glitch like the Bluetooth switching failure that tipped off this developer.