AliExpress fingerprinted browsers with inaudible Web Audio tones
Matthew Callaghan found obfuscated scripts that generated an inaudible sawtooth through the Web Audio API, with gain set to zero. The Register tied the files to Alibaba anti-abuse tooling.

On August 24 Ars Technica reported that researcher Matthew Callaghan found obfuscated scripts on AliExpress generating an inaudible sawtooth through the Web Audio API. Gain was set to zero. The tones were still enough to steal a Bluetooth-headphone fingerprint from a phone.
What we know
- Matthew Callaghan found obfuscated scripts that generated an inaudible sawtooth via the Web Audio API.
- The scripts stole a Bluetooth-headphone fingerprint from a phone; gain was set to zero.
- Firefox 118 and later, and Chrome, use their own math, which reduces the entropy of the signal.
- The Register identified collina.js and fireyejs.js as Alibaba anti-abuse tooling.
Takeaways
- Silence in the speakers did not mean the Audio API was idle.
- Headphones on a phone became another identifier.
- The scripts match Alibaba’s known anti-abuse stack, not a random third-party widget.
Source: Ars Technica


