London Daily

Focus on the big picture.
Sunday, Nov 16, 2025

Apple browser bug could lead to personal data leak

Apple browser bug could lead to personal data leak

A vulnerability in the Safari 15 browser allows malicious programs to track people’s internet activity and reveal their identity
A recently disclosed Apple Safari 15 bug can be used by nefarious sites to extract people’s browsing history and obtain their Google ID to collect more personal data, a fraud detector reports.

The problem identified by FingerprintJS, a browser fingerprinting fraud detection service, resides with IndexedDB – an application programming interface, or API, used to store large amounts of data on a browser.

Normally, such data collecting interfaces operate within the ‘same-origin’ policy: they only allow websites a person interacts with to access data generated by each such website itself but not the other ones. For example, if a person opens their email account in one browser tab and another webpage in the second one, this webpage would not be able to access any email-related data.

When it comes to Safari 15, though, this is not the case. Due to Apple’s application of the IndexedDB API, each time a website interacts with the browser database, a new database of the same name is created for all other active tabs. That means that each such site can access database names for all other sites a person interacts with at the same time.

This can be particularly disturbing when a person interacts with some web pages requiring some personal data like YouTube or Google accounts. Any Google ID-linked pages create databases with a person’s unique Google User ID in their names, which are then de-facto shared with all other websites a person opens and can thus be potentially exploited by nefarious actors, including to obtain more personal data once they know the Google ID.

MacOS owners can potentially just use a browser other than Safari to get around the bug but there is little iPhone and iPad owners can do since Apple’s third-party browser engine ban on all iOS devices means all browsers are affected. Private mode on Safari 15 is affected as well.

FingerprintJS even created a special demo to show how website data, browsing history and personal data are collected by Safari in a way that reveals a person’s internet profile picture. It also said it reported the issue to the WebKit Bug Tracker on November 28, but no updates to fix the issue have been released as of yet. Apple also has not answered media requests for comment so far.
Newsletter

Related Articles

0:00
0:00
Close
Nearly Half of Job Losses Under Labour Government Affect UK Youth
UK Chancellor Reeves Eyes High-Value Home Levy in Budget to Raise Tens of Billions
UK Urges Poland to Choose Swedish Submarines in Multi-Billion € Defence Bid
US Border Czar Tom Homan Declares UK No Longer a ‘Friend’ Amid Intelligence Rift
UK Announces Reversal of Income Tax Hike Plans Ahead of Budget
Starmer Faces Mounting Turmoil as Leaked Briefings Ignite Leadership Plot Rumours
UK Commentator Sami Hamdi Returns Home After US Visa Revocation and Detention
UK Eyes Denmark-Style Asylum Rules in Major Migration Shift
UK Signals Intelligence Freeze Amid US Maritime Drug-Strike Campaign
TikTok Awards UK & Ireland 2025 Celebrates Top Creators Including Max Klymenko as Creator of the Year
UK Growth Nearly Stalls at 0.1% in Q3 as Cyberattack Halts Car Production
Apple Denied Permission to Appeal UK App Store Ruling, Faces Over £1bn Liability
UK Chooses Wylfa for First Small Modular Reactors, Drawing Sharp U.S. Objection
Starmer Faces Growing Labour Backlash as Briefing Sparks Authority Crisis
Reform UK Withdraws from BBC Documentary Amid Legal Storm Over Trump Speech Edit
UK Prime Minister Attempts to Reassert Authority Amid Internal Labour Leadership Drama
UK Upholds Firm Rules on Stablecoins to Shield Financial System
Brussels Divided as UK-EU Reset Stalls Over Budget Access
Prince Harry’s Remembrance Day Essay Expresses Strong Regret at Leaving Britain
UK Unemployment Hits 5% as Wage Growth Slows, Paving Way for Bank of England Rate Cut
Starmer Warns of Resurgent Racism in UK Politics as He Vows Child-Poverty Reforms
UK Grocery Inflation Slows to 4.7% as Supermarkets Launch Pre-Christmas Promotions
UK Government Backs the BBC amid Editing Scandal and Trump Threat of Legal Action
UK Assessment Mis-Estimated Fallout From Palestine Action Ban, Records Reveal
UK Halts Intelligence Sharing with US Amid Lethal Boat-Strike Concerns
King Charles III Leads Britain in Remembrance Sunday Tribute to War Dead
UK Retail Sales Growth Slows as Households Hold Back Ahead of Black Friday and Budget
Shell Pulls Out of Two UK Floating Wind Projects Amid Renewables Retreat
Viagogo Hit With £15 Million Tax Bill After HMRC Transfer-Pricing Inquiry
Jaguar Land Rover Cyberattack Pinches UK GDP, Bank of England Says
UK and Germany Sound Alarm on Russian-Satellite Threat to Critical Infrastructure
Former Prince Andrew Faces U.S. Congressional Request for Testimony Amid Brexit of Royal Title
BBC Director-General Tim Davie and News CEO Deborah Turness Resign Amid Editing Controversy
Tom Cruise Arrives by Helicopter at UK Scientology Fundraiser Amid Local Protests
Prince Andrew and Sarah Ferguson Face Fresh UK Probes Amid Royal Fallout
Mothers Link Teen Suicides to AI Chatbots in Growing Legal Battle
UK Government to Mirror Denmark’s Tough Immigration Framework in Major Policy Shift
UK Government Turns to Denmark-Style Immigration Reforms to Overhaul Border Rules
UK Chancellor Warned Against Cutting Insulation Funding as Budget Looms
UK Tenant Complaints Hit Record Levels as Rental Sector Faces Mounting Pressure
Apple to Pay Google About One Billion Dollars Annually for Gemini AI to Power Next-Generation Siri
UK Signals Major Shift as Nuclear Arms Race Looms
BBC’s « Celebrity Traitors UK » Finale Breaks Records with 11.1 Million Viewers
UK Spy Case Collapse Highlights Implications for UK-Taiwan Strategic Alignment
On the Road to the Oscars? Meghan Markle to Star in a New Film
A Vote Worth a Trillion Dollars: Elon Musk’s Defining Day
AI Researchers Claim Human-Level General Intelligence Is Already Here
President Donald Trump Challenges Nigeria with Military Options Over Alleged Christian Killings
Nancy Pelosi Finally Announces She Will Not Seek Re-Election, Signalling End of Long Congressional Career
UK Pre-Budget Blues and Rate-Cut Concerns Pile Pressure on Pound
×