A San Francisco-based developer discovered that Alibaba Group's AliExpress marketplace secretly hijacked his computer's audio system through hidden browser scripts, allowing the website to run inaudible sound waves at zero volume to create "fingerprints" used to track devices without relying on cookies.
The privacy-focused Brave browser revealed in a series of X posts that the AliExpress marketplace was keeping the developer's computer audio system active through hidden browser scripts, potentially allowing the website to generate a unique identifier for his device.
The issue emerged when the developer's Bluetooth headphones refused to transfer their audio connection from his computer to his phone while AliExpress was open. A deeper dive of the website's code showed background scripts maintaining access to the computer's audio-processing system without producing audible sound.
The scripts allegedly used the browser's Web Audio API to process signals at zero volume. Small differences in how individual computers handle those signals can be measured and combined into an "audio fingerprint," allowing websites to recognize devices even when cookies are deleted or blocked.
Alibaba's AliExpress was caught using users' audio systems to track them.
— Brave (@brave) August 22, 2026
AliExpress wasn't recording users but instead playing a silent sound and measuring how users' specific devices processed it in order to fingerprint them.
But don't worry because Brave stops this.
The developer also found