securityonline.info 8/23/2026, 10:41:29 AM · external

AliExpress hides audio scripts that hijack Bluetooth headphones

AliExpress hides audio scripts that hijack Bluetooth headphones
CyberSIXT Evidence Panel
Primary Source blog.laserphile.com

A researcher uncovered a hidden feature on the AliExpress website where audio fingerprinting scripts operate without user knowledge. This issue started when their Bluetooth headphones disconnected due to the AliExpress homepage loading. Upon investigation, two obfuscated scripts (`collina.js` and `fireyejs.js`) were found creating silent WebAudio contexts that prevented the headphones from functioning correctly.

These scripts not only engage audio systems but also collect extensive user data, such as canvas rendering and hardware details, to create a unique browser fingerprint. While this fingerprint helps combat fraud, it raises privacy concerns about trust in online activity. The researcher suggests using uBlock Origin to block these scripts, albeit with potential side effects like triggering CAPTCHAs.

View Primary Source Via securityonline.info

Article by CyberSIXT