TechNewsReel
Live

AliExpress uses silent audio signals to fingerprint users, causing hardware glitches

Developer Matt Callaghan discovered the e-commerce giant uses WebAudio scripts to track shoppers, inadvertently breaking Bluetooth multipoint switching.

TechNewsReel Newsroom · August 24, 2026

AliExpress is facing scrutiny after a developer discovered the platform uses silent audio signals to fingerprint users for tracking purposes. The discovery reveals how invisible telemetry can interfere with physical hardware, creating a tangible impact on the user experience.

Developer Matt Callaghan first noticed the issue when his multipoint Bluetooth headphones failed to switch back to his phone while the AliExpress homepage was open. "Shortly after loading the AliExpress homepage, audio from my phone would stop playing," Callaghan reported, noting that closing the tab immediately resolved the problem. His investigation revealed that the site employs WebAudio scripts that generate audio signals with zero gain. While these signals are inaudible to the human ear, they keep the browser's audio path active, which tricked Callaghan's headphones into remaining connected to the computer.

The Mechanics of Audio Fingerprinting

Browser fingerprinting is a sophisticated tracking technique used to identify unique users by analyzing their specific hardware and software configurations. Unlike cookies, which are stored on the user's device, fingerprinting relies on the unique way a device processes data. In this instance, AliExpress uses a WebAudio graph to measure how different browsers and hardware implementations process audio signals. By analyzing the resulting frequency data, the platform can create a unique identifier for the device, allowing it to track users even if they clear their browser history or use privacy-focused settings.

Implications for Privacy and Hardware

This case underscores the ongoing arms race between e-commerce giants and browser privacy protections. While many modern browsers have implemented defenses against standard tracking, the use of the WebAudio API demonstrates a move toward more invasive, "silent" mechanisms that bypass traditional blocks. The fact that this tracking had a direct, negative effect on Bluetooth multipoint switching highlights a critical blind spot in web telemetry: scripts designed for data collection can inadvertently degrade the functionality of the user's physical hardware.

The Path Forward

The discovery further emphasizes the disparity in fingerprinting defenses across the browser landscape, with platforms like Brave and Firefox typically offering more robust protections than Chrome. As e-commerce platforms continue to refine their telemetry efforts to collect device and browser data, users and developers are left to monitor how these invisible scripts impact both digital privacy and hardware stability. It remains to be seen if Alibaba will modify these scripts to prevent hardware interference or if browser vendors will implement stricter limits on the WebAudio API to curb such tracking.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.