A recent investigation by developer Matt Callaghan has revealed that AliExpress may be utilizing silent audio techniques to fingerprint users visiting its website. This discovery was prompted by an unusual issue with Callaghan’s Bluetooth headphones, which ceased playing audio from his phone when he accessed the AliExpress homepage.
Incident Overview
Callaghan noted that his headphones, capable of connecting to multiple devices, typically prioritize audio from his PC. However, upon loading the AliExpress site in either Firefox or Chrome, audio from his phone would stop. He found that closing the AliExpress tab resolved the issue, and muting the tab or the browser did not help, indicating that there was no visible media playing on the page.
Technical Findings
Upon further investigation, Callaghan discovered two obfuscated audio scripts within the site’s code. These scripts created a WebAudio graph that generated a silent sawtooth waveform, allowing the browser to process audio without producing sound. This method effectively kept the Bluetooth audio path active, interfering with the expected functionality of his headphones.
Browser Responses and Protections
Callaghan’s findings prompted responses from both Firefox and Brave. Firefox stated that its anti-fingerprinting technology, introduced in version 118 in September 2023, mitigates the effectiveness of WebAudio-based fingerprinting by grouping users into broad categories, thereby reducing the precision of tracking. According to Firefox, 99.24% of users fall into one of three categories based on hardware specifications, making individual tracking less effective.
Brave also confirmed its long-standing protection against fingerprinting, stating that it injects random data into browser output to alter fingerprints across different sites. Additionally, Brave blocks the specific scripts used by AliExpress for this tracking method by default.
Current Status and Implications
While Callaghan’s claims regarding AliExpress’s tracking methods have been noted, the company has yet to respond to requests for comment. The implications of this incident highlight ongoing concerns about user privacy and the methods employed by websites to track individuals without their consent. As browser technologies evolve, the effectiveness of such tracking techniques may continue to be challenged.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








