AliExpress Uses Silent Web Audio Fingerprinting to Track Visitors’ Browsers
What Happened — Researchers from Malwarebytes and the Brave browser team discovered that AliExpress runs a hidden Web Audio graph that emits an inaudible signal, captures the device’s acoustic response, and combines the measurements with canvas, WebGL, WebRTC and hardware data to create a highly granular browser fingerprint. The audio processing runs at zero volume, so users hear nothing and muting the tab does not stop the collection.
Why It Matters for Compliance & Audit Readiness
- The technique sidesteps traditional cookie‑based consent mechanisms, challenging the effectiveness of privacy‑control policies required by GDPR, CCPA and similar frameworks.
- Continuous‑compliance programs must be able to demonstrate that all data‑collection practices are documented, consented to, and mapped to privacy controls (e.g., SOC 2 CC6.1, CC6.2).
- Verisq’s CookiePLUS capability provides automated consent capture, DSAR readiness, and audit‑ready evidence that your site’s tracking scripts respect user‑choice and regulatory mandates.
Who Is Affected — Retail and e‑commerce platforms, ad‑tech providers, and any online service that embeds third‑party scripts capable of device fingerprinting.
Recommended Actions
- Conduct a privacy‑impact assessment of all client‑side scripts; inventory any Web Audio or similar fingerprinting code.
- Map the identified data‑flows to SOC 2 privacy criteria and update your consent‑management workflow to cover non‑cookie tracking.
- Deploy a consent‑management solution (e.g., CookiePLUS) that can capture, store, and prove user choices for all tracking techniques.
Source: Malwarebytes Labs
Technical Notes — The fingerprinting leverages the Web Audio API to generate a fixed waveform, measures minute variations caused by CPU, OS, audio drivers and hardware, and combines these with canvas, WebGL, display settings, WebRTC and interaction signals. No microphone access is required; the audio graph runs at zero gain, making it invisible to users. Source: Malwarebytes Labs