Privacy, Identity

Firefox and Tor Browser vulnerability allowed hidden identifiers

Firefox web browser under magnifying glass. Firefox is a free and open-source web browser developed by the Mozilla Foundation.

Researchers uncovered a critical flaw in Firefox and Tor Browser that allowed websites to generate hidden, stable identifiers without cookies, Tech Radar reports.

The vulnerability stemmed from the behavior of IndexedDB, a browser database used for storing large amounts of data. Researchers from Fingerprint discovered that the order in which IndexedDB returned entries was not random but reflected internal browser processes. This predictable order could be exploited by malicious websites to create a unique, persistent identifier for users, even when using private browsing modes or Tor Browser's "New Identity" feature.

This method allowed for tracking users without relying on traditional cookies or other obvious tracking mechanisms. Both Mozilla and the Tor Project responded swiftly, releasing patches to address the vulnerability. 

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds