AliExpress deploys silent WebAudio fingerprinting on its website that interferes with Bluetooth multipoint functionality on user devices. The script runs without explicit user consent.
Security researchers discovered that AliExpress injects WebAudio fingerprinting code into its pages, a technique typically used for device identification and fraud prevention. The fingerprinting process executes audio operations that inadvertently disrupt Bluetooth multipoint—the ability to connect a single device to multiple audio outputs simultaneously.
When users visit AliExpress, the WebAudio API creates audio contexts that claim exclusive device access, blocking competing Bluetooth connections. This affects wireless headphones, speakers, and other audio peripherals attempting to maintain multipoint pairing.
The issue impacts any browser-based Bluetooth audio device while the AliExpress site remains open or active in a tab. Users report losing connectivity to secondary audio devices until the site is closed or refreshed.
AliExpress has not publicly addressed the discovery. The fingerprinting appears designed for device tracking rather than intentional disruption, but the technical consequence remains problematic for users relying on Bluetooth multipoint features. The finding highlights how fingerprinting techniques can have unintended side effects beyond their intended purpose.
Citrix has issued an urgent warning for administrators to patch two vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The flaws pose immediate security risks to remote access and networking infrastructure.
The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform.
A new Android malware called Manic is targeting users across multiple European countries and uses a novel data exfiltration method through nearby infected devices.
Security defenses effectively block known attack methods but often fail against behavioral variants that achieve the same objectives through different techniques, according to Picus Security's Blue Report 2026.