News: 1642444267

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Bug in WebKit's IndexedDB implementation makes Safari 15 leak Google account info... and more

(2022/01/17)


An improperly implemented API that stores data on browsers has caused a vulnerability in Safari 15 that leaks user internet activity and personal identifiers.

The vulnerability was discovered by fraud detection service [1]Fingerprint JS , which has contacted the WebKit maintainers and provided a public [2]source code repository .

As of 28 November last year, the issue had not been fixed, so the team at Fingerprint JS decided to make the finding public to encourage the expedition of its repair.

[3]

The commonly used low-level JavaScript API, called IndexedDB, follows same-origin policy, meaning documents or scripts associated with one origin should not interact with resources associated with other origins. A webpage opened in one tab of the browser should not be able to share data with the next tab, for obvious reasons, such as if one tab was used to access a user's bank and the other a malicious website.

[4]

[5]

But in the case of this particular indexed database, the separate pages do interact, putting the user at risk. When using Safari 15, which relies on IndexedDB, every time a website interacts with a database, a new empty one with the same name is created in all active frames, tabs, and windows in the same browser session. This results in other websites having access to the name of the databases. The Safari bug can then expose publicly available information from, say, a Google account.

Users logged into their Google account will have their unique Google User ID placed into the database's name. Database names can then be used to extract identifying information from a lookup table if sites scrape the Google User ID and use it to find personal information.

[6]

But not only can a malicious website learn the user's identity, it can stitch together multiple separate accounts from the same user without that person even doing anything, other than running a window in the background. The malicious website can open other websites, if programmed in an iframe or popup, and thus open a Pandora's box of leaking data.

Fingerprint JS made a video explaining the process:

[7]Youtube Video

[8]A slice is better than none: Apple gives in, allows third-party app billing systems in Korea, per local law

[9]Bad Apple Safari update breaks IndexedDB JavaScript API, upsets web apps

[10]Apple: We're defending your privacy by nixing 16 browser APIs. Rivals: You mean defending your bottom line

[11]IndexedDB pulls away from less-loved web storage options

The team found that more than 30 websites out of the Alexa Top 1000 interacted with indexed databases on their homepage without the user doing anything, and they reckon there are tons more out there.

Sadly, browsing in Private Mode didn't solve the problem, although the extent of information available via the leak is more limited by nature of the tool.

[12]

The fraud detection service created a [13]demo to identify the sites a Google account user has open or opened recently. It looks for over 20 specific websites it knows are problematic when used in combination with Safari 15 on macOS, iOS 15 or iPadOS 15 as Apple requires WebKit be used with those browsers, and a Google account.

Other than blocking JavaScript, not using Google accounts or switching to different browsers if available (not available for iOS and iPadOS) while surfing the web on an Apple product, there's not much to be done other than wait it out, said the team.

It's all a bit ironic given that in June 2020, Apple [14]refused to implement 16 web APIs into Safari's WebKit engine, claiming they posed a privacy threat. Some researchers applauded the move as a win for privacy, but many met the decision with derision, saying the action was done to force the use of native iOS apps and the income they bring in.

Of course, this sort of our-product-only approach goes beyond browsers for the company. Just last week Apple was forced to stop dragging its feet and allow [15]third-party app billing systems in Korea per the country's Telecommunications Business Act. Google was given a command to do the same in September and compiled in November – over two months prior to Apple.

Steamrolling use of WebKit and thus IndexedDB has been problematic in the past. A bug in Safari 14.1.1 on macOS 11.4 and iOS 14.6 that manifests when applications first try to use IndexedDB NoSQL manager to store data [16]caused user outrage last June. One open-source developer referred to Apple as being "outright hostile to the web." ®

Get our [17]Tech Resources



[1] https://fingerprintjs.com/blog/indexeddb-api-browser-vulnerability-safari-15/

[2] https://github.com/fingerprintjs/blog-indexeddb-safari-leaks-demo

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YeX1FVB-GDN1Sp2lvNtbfQAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeX1FVB-GDN1Sp2lvNtbfQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeX1FVB-GDN1Sp2lvNtbfQAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeX1FVB-GDN1Sp2lvNtbfQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://youtu.be/Z7dPeGpCl8s

[8] https://www.theregister.com/2022/01/12/apple_third_party_payments/

[9] https://www.theregister.com/2021/06/16/apple_safari_indexeddb_bug/

[10] https://www.theregister.com/2020/06/29/apple_web_developers/

[11] https://www.theregister.com/2016/10/26/web_app_storage_matures/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeX1FVB-GDN1Sp2lvNtbfQAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://safarileaks.com/

[14] https://www.theregister.com/2020/06/29/apple_web_developers/

[15] https://www.theregister.com/2022/01/12/apple_third_party_payments/

[16] https://www.theregister.com/2016/10/26/web_app_storage_matures/

[17] https://whitepapers.theregister.com/



msobkow

Just puts the boots to Apple's claims about being concerned about "security" not their cash cow when they're talking the app store.

TITSUP*

HildyJ

Apple's decision to maintain its walled garden makes it vulnerable to problems when interacting with non-Apple software. Ideally they would collaborate more to anticipate, mitigate, and correct problems but this seems as likely as their starting to respond th ElReg's requests for comments.

* Total Inability To Secure User Privacy

Re: TITSUP*

b0llchit

Apple's decision to maintain its walled garden makes it vulnerable to problems when interacting with non-Apple software.

In other words, functioning as designed. The walled garden is there to prevent non-Apple software from interfering with Apple profits. Therefore, non-Apple software is strongly discouraged and deprecated. The ability to run non-Apple software will soon be removed.

it would be a joke if this scenario was unthinkable

Not Irrelevant

Apple's lack of 3rd party browsers on iDevices should be criminal.

Privacy? We've not even heard of it!

Brewster's Angle Grinder

This is equivalent to finding you can read files that are chmod 600 for other users. It's that much of an epic failure.

Whatever

Ace2

I will still take web services controlled by Apple over web services controlled by Google, any day of the week.

Re: Whatever

Korev

Me too, also the reason why I switched from Android to iPhone

Re: Whatever

msobkow

I do not understand the rationale of choosing to go with the more expensive and invasive of the evils. If you think Apple is really any better than Google, I direct you to a history of charges, claims, and lawsuits over the years, on a variety of issues.

Apple just plays the public perception card of being "security conscious"; it doesn't mean they are any better than anyone else at actually implementing and enforcing security and quality software.

Thank you for drinking Apple's kool-aid and paying your tithe for choosing an iThing instead of the cheaper and equally invasive eThing from an alternate vendor.

They all reap you as their data feed. All of them. No exceptions. YOU are both market and product.

Like politicians, they will say anything to get you to steer your votes/dollars in their direction. Don't mistake "The Message" for reality.

How long ago?

grizewald

"As of 28 November last year, the issue had not been fixed"

So there's a major credential stealing bug in Safari which has been public since 28 Nov 2021? We are hearing about it now on the 17 Jan 2022??

Seriously?????

"One basic notion underlying Usenet is that it is a cooperative."

Having been on USENET for going on ten years, I disagree with this.
The basic notion underlying USENET is the flame.
-- Chuq Von Rospach