AliExpress was fingerprinting browsers with silent Web Audio, found because it broke a dev's Bluetooth headphones
Reported 2026-08-24 across Ars Technica, The Register and Malwarebytes, AliExpress was running silent Web Audio API processing to fingerprint visitors without cookies, generating an inaudible signal at zero volume and measuring small repeatable differences in how each browser and device handled it. Developer Matt Callaghan found it because the open tab kept dropping his Bluetooth headphones by interfering with multipoint device switching. Multiple outlets correct the widely repeated 'ultrasound' framing: nothing leaves the speakers, the measurement is purely digital. Brave announced on 2026-08-22 that it blocks the responsible AliExpress scripts, and says it has defaulted to audio-fingerprinting protection for over six years.
Source
↳ Follow the thread