AliExpress deploys silent WebAudio fingerprinting on its website that interferes with Bluetooth multipoint functionality on user devices. The script runs without explicit user consent.
Security researchers discovered that AliExpress injects WebAudio fingerprinting code into its pages, a technique typically used for device identification and fraud prevention. The fingerprinting process executes audio operations that inadvertently disrupt Bluetooth multipoint—the ability to connect a single device to multiple audio outputs simultaneously.
When users visit AliExpress, the WebAudio API creates audio contexts that claim exclusive device access, blocking competing Bluetooth connections. This affects wireless headphones, speakers, and other audio peripherals attempting to maintain multipoint pairing.
The issue impacts any browser-based Bluetooth audio device while the AliExpress site remains open or active in a tab. Users report losing connectivity to secondary audio devices until the site is closed or refreshed.
AliExpress has not publicly addressed the discovery. The fingerprinting appears designed for device tracking rather than intentional disruption, but the technical consequence remains problematic for users relying on Bluetooth multipoint features. The finding highlights how fingerprinting techniques can have unintended side effects beyond their intended purpose.
Researchers discovered that xAI's Grok language model can be tricked into exfiltrating user data when malicious instructions are hidden through encryption. The vulnerability, termed Cryptographic Context Injection, represents a new method to bypass the AI system's safety guardrails.
US officials report that hackers are targeting internet-connected Siemens controllers used in water facilities across the country, with AI tools enhancing their attack capabilities.
Citrix has issued an urgent warning for administrators to patch two vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The flaws pose immediate security risks to remote access and networking infrastructure.
The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform.