A developer has found that the AliExpress homepage can silently run audio-processing code to help build a detailed device fingerprint. The reported AliExpress audio tracking method does not record conversations, but it may collect device-specific signals without clear notice to users.
Hidden audio processing affected Bluetooth headphones
The developer, known as laserphile, noticed a strange problem while using Bluetooth headphones with multipoint support.
When the AliExpress website was open on a PC, audio playing from a connected phone stopped. Closing the browser tab immediately resolved the problem.
The developer found no visible media, audio player or video on the page. However, an investigation identified two hidden WebAudio processing contexts that connected to the computer’s audio output.
Silent signals can support device fingerprinting
The scripts reportedly generate a known waveform and analyse how the browser and hardware process it. Their volume is set to zero, so users should not hear anything.
This process can reveal subtle differences between devices, browser versions, operating systems and audio libraries. On its own, audio data may not uniquely identify a device. However, it becomes more useful when combined with other browser signals.
The reported AliExpress audio tracking scripts also collected data linked to canvas rendering, WebGL, display settings, hardware specifications, browser plugins, WebRTC behaviour and user interactions.
The scripts then encrypted and sent the collected data to Alibaba telemetry services, according to the developer’s analysis.
Alibaba scripts may support fraud prevention
Large online marketplaces often use device fingerprinting to detect fraud, fake accounts, automated shopping, coupon abuse and suspicious activity.
However, the developer could not determine how AliExpress uses the collected data after it reaches Alibaba’s servers. The browser code does not reveal whether the company keeps the fingerprints long term or links them across its services.
The developer said the technique caused a real hardware side effect by keeping the PC’s Bluetooth audio path active. As a result, the headphones could not switch cleanly back to the phone.
Users can block the identified scripts
The developer tested blocking the two identified AliExpress script families with a content blocker. After blocking them, the hidden audio contexts no longer appeared and the Bluetooth issue stopped.
However, blocking anti-fraud scripts could create problems during login or checkout. Users may see additional CAPTCHA requests or encounter payment issues.
The reported AliExpress audio tracking method highlights how websites can collect extensive browser and device data without using cookies. It also raises questions about transparency when retailers use hidden fingerprinting tools on ordinary shopping pages.


0 responses to “AliExpress Audio Tracking Scripts Raise Privacy Concerns”