Overview
- A developer investigating multipoint Bluetooth headphone failures found that an AliExpress tab created Web Audio API graphs set to zero gain that remained connected to the system audio path and blocked device switching.
- The site generated an inaudible waveform and measured tiny, repeatable differences in how a browser and device processed it, which researchers say can serve as an audio‑based fingerprint without recording through microphones.
- Analysts found the audio measurements were combined with canvas rendering, WebGL, display and hardware details, WebRTC behavior and user interactions to create a stronger, multi-signal device identifier.
- Brave has publicly flagged and blocks the scripts and other browsers can use content blockers such as uBlock Origin, but blocking these scripts may disrupt AliExpress features that rely on the same security or anti‑fraud tooling and there is no detailed public response from AliExpress or Alibaba.
- Fingerprinting is a growing alternative to cookies for fraud prevention and bot detection, and this case highlights a policy and product trade-off that will likely drive more browser defenses, user mitigations, and possible regulatory scrutiny.