AliExpress Caught Using Inaudible Sound to Track Web Browsers
Tech

AliExpress Caught Using Inaudible Sound to Track Web Browsers

šŸ“… Tuesday, August 25, 2026Ā·ā± 3 min readĀ·šŸ‘ 0 views

Photo: Joshua Oluwagbemiga

Researchers have discovered AliExpress using high-frequency audio signals to create unique browser fingerprints, raising significant online privacy concerns.

#privacy#cybersecurity#AliExpress#web tracking#tech news

A startling discovery has exposed the lengths to which some e-commerce giants will go to track their users. Security researchers recently found that the shopping platform AliExpress has been utilizing inaudible, high-frequency sound signals to 'fingerprint' web browsers. This sophisticated tracking method allows the site to identify and link specific users even when they attempt to remain anonymous or clear their traditional tracking cookies.

Browser fingerprinting is a technique where websites collect a variety of technical data points from a user's browser, such as screen resolution, installed fonts, and operating system details. By combining these pieces of information, companies can generate a unique identifier for a device. While this is often used for security, such as detecting fraud, it is increasingly being weaponized for invasive advertising and behavior tracking without explicit user consent.

The research, detailed in a report covered by Ars Technica, highlights a specific implementation involving the Ultrasonic Cross-Device Tracking (uXDT) concept. In this instance, the website triggers high-frequency sounds from a user’s computer speakers. These sounds, which are largely imperceptible to the human ear, serve as a beacon that can be detected by other nearby devices or even through browser-based APIs. The goal is to create a persistent profile of the user that survives even after they have deleted their browser cache.

Experts explain that this method is particularly insidious because it operates largely outside the view of standard privacy tools. Most ad-blockers and privacy-focused browsers are designed to catch malicious scripts or third-party cookies, but they are not always equipped to detect or block the manipulation of audio APIs or the sophisticated signal processing required for ultrasonic tracking. By effectively 'tagging' the user via sound, AliExpress and similar entities can link a person’s mobile phone usage to their desktop browsing habits, creating a seamless trail of data that spans multiple devices.

The implications for privacy are profound. Modern digital privacy is built on the assumption that users have control over their data, usually managed through cookie consent banners or 'Do Not Track' requests. Ultrasonic fingerprinting bypasses these controls entirely. Because the technology exploits standard hardware capabilities—like the speaker and microphone functions of a computer—it turns a device’s fundamental features into a surveillance tool. This creates a scenario where users are tracked not by what they click, but by the physical characteristics of their hardware.

As digital privacy advocates continue to scrutinize the tech industry, this case serves as a reminder of the 'cat and mouse' game played between web developers and security researchers. While AliExpress is the latest to be caught, cybersecurity professionals suggest that this practice may be more widespread than the public realizes. The discovery underscores the need for browsers to implement stricter permissions for audio-related APIs, ensuring that websites cannot trigger audio events without clear and intentional interaction from the user.

For now, the best defense for privacy-conscious users remains the use of hardened browsers like Tor or Firefox with strict 'Enhanced Tracking Protection' enabled. Additionally, users can check their browser settings to ensure that the 'AudioContext' and other hardware-level APIs are restricted or disabled for websites that do not require them to function. As awareness of these techniques grows, regulatory bodies may soon be forced to classify ultrasonic tracking as a violation of existing data privacy laws, potentially leading to significant legal consequences for companies that continue to employ such methods.

This article was generated based on trending topic: ā€œInaudible sounds used to fingerprint browsers catch AliExpress red handed - Ars Technicaā€


Found this article helpful? Share it!

Related Articles

Comments