Begin forwarded message:
> From: Monty Solomon <[email protected]> > Date: January 18, 2022 at 22:47:38 EST > Subject: Safari and iOS users: Your browsing activity is being leaked in real > time > > Safari and iOS users: Your browsing activity is being leaked in real time > > For the past four months, Apple’s iOS and iPadOS devices and Safari browser > have violated one of the Internet’s most sacrosanct security policies. The > violation results from a bug that leaks user identities and browsing activity > in real time. > > The same-origin policy is a foundational security mechanism that forbids > documents, scripts, or other content loaded from one origin—meaning the > protocol, domain name, and port of a given webpage or app—from interacting > with resources from other origins. Without this policy, malicious sites—say, > badguy.example.com—could access login credentials for Google or another > trusted site when it’s open in a different browser window or tab. > > ... > > https://arstechnica.com/information-technology/2022/01/safari-and-ios-bug-reveals-your-browsing-activity-and-id-in-real-time/ > > > Exploiting IndexedDB API information leaks in Safari 15 > https://fingerprintjs.com/blog/indexeddb-api-browser-vulnerability-safari-15/ > >
-- Iw mailing list [email protected] http://sticklist.org/mailman/listinfo/iw_sticklist.org
