Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

AliExpress Uses Silent Web Audio Fingerprinting to Track Visitors' Browsers

AliExpress runs a hidden Web Audio graph that emits an inaudible signal and measures device‑specific acoustic responses, creating a detailed fingerprint without user consent. This bypasses cookie‑based privacy controls, prompting compliance teams to reassess consent and data‑handling practices.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

AliExpress Uses Silent Web Audio Fingerprinting to Track Visitors’ Browsers

What Happened — Researchers from Malwarebytes and the Brave browser team discovered that AliExpress runs a hidden Web Audio graph that emits an inaudible signal, captures the device’s acoustic response, and combines the measurements with canvas, WebGL, WebRTC and hardware data to create a highly granular browser fingerprint. The audio processing runs at zero volume, so users hear nothing and muting the tab does not stop the collection.

Why It Matters for Compliance & Audit Readiness

  • The technique sidesteps traditional cookie‑based consent mechanisms, challenging the effectiveness of privacy‑control policies required by GDPR, CCPA and similar frameworks.
  • Continuous‑compliance programs must be able to demonstrate that all data‑collection practices are documented, consented to, and mapped to privacy controls (e.g., SOC 2 CC6.1, CC6.2).
  • Verisq’s CookiePLUS capability provides automated consent capture, DSAR readiness, and audit‑ready evidence that your site’s tracking scripts respect user‑choice and regulatory mandates.

Who Is Affected — Retail and e‑commerce platforms, ad‑tech providers, and any online service that embeds third‑party scripts capable of device fingerprinting.

Recommended Actions

  • Conduct a privacy‑impact assessment of all client‑side scripts; inventory any Web Audio or similar fingerprinting code.
  • Map the identified data‑flows to SOC 2 privacy criteria and update your consent‑management workflow to cover non‑cookie tracking.
  • Deploy a consent‑management solution (e.g., CookiePLUS) that can capture, store, and prove user choices for all tracking techniques.

Source: Malwarebytes Labs

Technical Notes — The fingerprinting leverages the Web Audio API to generate a fixed waveform, measures minute variations caused by CPU, OS, audio drivers and hardware, and combines these with canvas, WebGL, display settings, WebRTC and interaction signals. No microphone access is required; the audio graph runs at zero gain, making it invisible to users. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/privacy/2026/08/aliexpress-caught-using-silent-audio-to-fingerprint-visitors-browsers ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →