Security News > 2022 > January > Serious Security: Apple Safari leaks private data via database API – what you need to know
data:image/s3,"s3://crabby-images/423df/423dfaff485cc962b6734c0c89b43e52ece2e4d1" alt="Serious Security: Apple Safari leaks private data via database API – what you need to know"
Researchers at browser identification company FingerprintJS recently found and disclosed a fascinating data leakage bug in Apple's web browser software.
At first telling, the bug sounds both undramatic and unimportant: although it allows private data to leak between separate browser tabs that contain content from unrelated websites, the amount of data that leaks is minuscule.
WebKit, like all other modern browser engines, lets websites set and store what's called stateful data - information that's carried from one visit to a site to the next, traditionally via web cookies.
As you can imagine, the sort of data stored in cookies and web storage isn't suitable for disclosing to anyone, given that it often identifies you loosely, and frequently identifies you exactly - for example, cookies may grant access to private data in an online account, such as your name, address, contact details, credit card data, as well as the password reset page for that account.
We now have THREE types of local storage: cookies, which are great for simple settings such as pagestyle=dark; web storage, fine for larger-sized chunks of data such as configuration settings and modestly-sized documents; and a local database system known as IndexedDB, when you need to keep large amounts of data and to access it efficiently.
Clearing web data typically means you need to need to login and readjust preferences for every website you've used lately.
News URL
Related news
- Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API (source)
- UN aviation agency confirms recruitment database security breach (source)
- Apple plugs security hole in its iThings that's already been exploited in iOS (source)
- SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon (source)
- Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek (source)
- The API security crisis and why businesses are at risk (source)