Chinese retailer AliExpress has been identified using hidden browser scripts that play inaudible audio to generate unique visitor fingerprints. This tracking technique reportedly caused hardware interference by forcing connected Bluetooth devices to drop their active audio streams.
The Discovery of Stealth Tracking
The discovery occurred when researcher Matthew Callaghan noticed his multipoint Bluetooth headphones repeatedly losing audio connectivity while browsing the web. Callaghan had his headphones configured to maintain a connection to his phone, only switching to his computer when audio was actively playing. He observed that every time he loaded the AliExpress homepage on his desktop browser, the phone audio would suddenly cut out, as if the computer was seizing control of the audio channel. Once he closed the browser tab associated with the retailer, the connection to his phone would automatically resume. This repetitive pattern of hardware interference served as the primary indicator that the website was executing unauthorized audio processes within the background of the browser session.
Technical Implementation of Audio Fingerprinting
Upon further technical investigation, Callaghan identified two highly obfuscated scripts embedded within the AliExpress site designed to facilitate stealthy tracking. These scripts utilized the browser's WebAudio API to generate a specific waveform, which acted as a data-measuring oscillator. By measuring how the user's unique browser audio implementation processed these generated Sawtooth waves, the scripts were able to compile a unique identifier for the machine. To ensure the process remained invisible to the end user, the scripts set the audio gain to zero, effectively rendering the sound inaudible to human ears. However, even at zero volume, the computer system and browser continue to process the signal, which is then captured and transmitted back to the retailer's servers to complete the fingerprinting process.
Implications for User Privacy
This incident highlights a sophisticated category of digital surveillance known as browser fingerprinting, which seeks to identify and track individuals without relying on traditional tracking cookies. By measuring subtle variations in how different hardware and software environments interpret digital signals, companies can maintain a persistent identity for a visitor even if the user clears their cache or employs privacy-focused browser configurations. While the use of inaudible audio for tracking is not an entirely new technique, the fact that this specific implementation was potent enough to disrupt peripheral hardware functionality underscores the invasive nature of modern web-based monitoring. The practice raises significant questions regarding consumer consent and the extent to which websites should be allowed to access hardware-level APIs for the purpose of non-essential data collection.
⚖ The Balanced View
Concerns & criticism
Security researchers and privacy advocates view the use of hidden audio scripts as a deceptive practice that hijacks hardware resources to facilitate non-consensual surveillance, noting that it can negatively impact user experience by interfering with peripheral devices.
→What's next
It remains to be seen whether browser vendors will implement stricter restrictions on WebAudio API access to prevent this specific type of tracking. Users concerned about similar activities may need to investigate browser-level settings that restrict background media or unauthorized audio output.
































































































































































































































































































