Researchers discovered AliExpress’s homepage running silent audio processes inside users’ browsers, using the Web Audio API at zero volume. The hidden activity interfered with Bluetooth headphone switching and appeared unrelated to normal media playback. The code, tied to Alibaba security systems, used device audio responses to create unique identifiers, alongside data from canvas rendering, WebGL, display settings, hardware details, WebRTC behavior, and user interactions, forming robust cross-session browser fingerprints. Privacy advocates warn users lack transparency or control over such tracking, even when cookies are cleared. Brave says its browser already blocks the AliExpress scripts, while other users may rely on content blockers, potentially disrupting security-related site features.
This update represents a notable development in the Ai sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.