AliExpress Faces Privacy Questions After Silent WebAudio Tracking Disrupts Bluetooth Headphones
AliExpress is facing fresh privacy concerns after researchers identified hidden WebAudio scripts on the e-commerce platform that can create a unique fingerprint of a user’s device while running silently in the background.
The discovery began when a developer noticed that opening AliExpress in a browser caused his Bluetooth multipoint headphones to stop switching audio from his computer to his phone. Closing the AliExpress tab immediately restored normal behaviour.
The investigation found two heavily obfuscated Alibaba scripts, identified as collina.js and fireyejs.js, creating WebAudio processing sessions connected to the system’s audio destination. The audio gain was set to zero, meaning users could not hear the generated signal even though the browser continued processing it.
Silent Audio Used for Device Fingerprinting
WebAudio fingerprinting is a technique that can analyse tiny differences in how a browser and computer process digital audio. Those differences can be combined with other technical characteristics to help distinguish one device from another without relying solely on traditional cookies.
Further examination of the scripts reportedly found code capable of gathering additional browser and hardware signals, including Canvas, WebGL, device memory, hardware concurrency, WebRTC and mouse or touch activity.
The scripts appear to be associated with Alibaba’s anti-fraud infrastructure, which can be used to identify suspicious automated activity and protect online services from abuse. However, the discovery has raised questions about how much information users may be providing without being clearly aware of the underlying browser activity.
Why Bluetooth Headphones Were Affected
The unusual tracking technique became visible because it apparently interfered with Bluetooth headphones supporting multipoint connections, which allow a headset to remain connected to two devices.
Although the AliExpress page produced no audible music or conventional media, its active WebAudio connection could keep the computer’s audio pathway occupied. That reportedly prevented headphones from automatically handing audio back to a connected phone. Muting the browser tab did not resolve the problem because there was no conventional audio or video element to mute.
Browser Makers Step Up Privacy Protection
The incident has also drawn attention to browser-level protections against fingerprinting.
Firefox has introduced measures that randomise WebAudio fingerprinting results, making it harder for websites to obtain a consistent device identifier through the technique. Brave also offers protections against audio fingerprinting and has reportedly blocked the specific scripts involved in the AliExpress case.
The episode highlights a broader privacy challenge facing internet users: modern tracking does not always require cookies, visible advertisements or even audible media.
As websites increasingly rely on sophisticated anti-fraud and identification technologies, the line between security, fraud prevention and user privacy is becoming harder to define.




