AliExpress Accused of Secretly Tracking Users with Audio Technology

AliExpress Accused of Secretly Tracking Users with Audio Technology

AliExpress was accused of utilising secret WebAudio fingerprinting routines to follow visitors without their knowledge. The trick was discovered by a developer who was visiting the shopping website and observed a weird issue with his Bluetooth headphones.

The developer discovered that his wireless headphones wouldn’t correctly switch audio to his phone when AliExpress was open. Then he looked at the website’s background code and saw that hidden Alibaba scripts were keeping his computer’s audio system on.

The action was tracked to two obfuscated anti-fraud scripts, named `collina.js` and `fireyejs.js`.

The technical investigation says the scripts are using the browser’s WebAudio API to create audio signals that are essentially quiet. The system takes these signals, but the user does not hear them.

The approach is used to identify very slight changes in the way a computer’s hardware and software handles audio calculations. Then these differences can be merged into a unique device fingerprint that helps to recognise the same user across different internet sessions.

Browser fingerprinting does not necessarily need to store an identification on a user’s device, unlike traditional cookies. Instead, websites can gather information about a browser and its hardware and merge that into a profile.

The research also discovered that the scripts captured information outside of audio processing. Their examination apparently included things like canvas and WebGL properties, hardware specs, WebRTC info, mouse and touch activities, and flags that could indicate automated browsing.

The concealed audio processing had an unanticipated effect. The audio system had been left on in the background, and it seemed to be interfering with the developer’s Bluetooth connection. The strange situation finally led to the discovery of the tracking mechanism.

The scripts could continue running even if the tab was muted or the browser was set to silent, because the audio processing was done via the WebAudio system, not via sound audible to the user.

Privacy-oriented browsers have included defences against this kind of tracking. For years, Brave has been protecting against audio fingerprinting by adding randomised data to browser output, making it harder for websites to build a consistent fingerprint. Firefox also has anti-fingerprinting tools to defend against WebAudio fingerprinting.

Brave has also disabled the precise scripts that AliExpress is using for this tracking tactic. The finding has led browser security teams to assess how well their existing defences work with this particular strategy.

The problem was first spotted by a Reddit user about a year ago, but the recent analysis gave a more in-depth look at how the trick worked.

The finding suggests an increasing usage of browser fingerprinting for tracking. Cookies can often be deleted or prevented. Fingerprinting can identify devices by combining several technological parameters exposed by the browser.

For users without privacy protections, the scripts listed above from AliExpress may still be running when browsing the homepage. The discoveries have prompted further concerns about how e-commerce companies deploy background anti-fraud and tracking technologies.

Previous Article

PIA Cabin Crew Jobs 2026 – Complete Guide (Apply Before 31 August)

Next Article

OGRA Increases Petrol and Diesel Prices Due to Global Oil Crisis

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter

Subscribe to our email newsletter to get the latest news delivered right to your email.
Subscribe to updated 🗞️