:

CHROMIUM 148 MATH.TANH CREATES NEW OS FINGERPRINT

INDUSTRY DESK1 MIN READ
SUN, JUL 12, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new browser fingerprinting vector has emerged in Chromium 148, where the Math.tanh function produces different results across operating systems. This discrepancy can be exploited to identify a user's underlying OS without explicit permission.

The Math.tanh JavaScript function, which calculates hyperbolic tangent values, now returns slightly different floating-point results depending on the host operating system. These variations stem from differences in CPU instruction implementations and mathematical libraries across Windows, macOS, and Linux. Browser fingerprinting works by collecting small identifying details about a user's system. While individual data points seem insignificant, combining multiple signals creates a unique profile that can track users across websites—even with cookies disabled or in private browsing mode. The discovery highlights how low-level mathematical operations can become privacy leaks. Developers and security researchers are discussing mitigation strategies on Hacker News, where the post generated significant engagement with 127 points and 52 comments. This joins a growing list of fingerprinting techniques exploiting browser APIs. Users concerned about privacy may consider browser extensions that spoof or randomize fingerprinting signals, though no universal solution currently exists.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A billing bug in Codex on AWS Bedrock is charging users approximately 10 times the expected rate. The issue was reported on GitHub and has generated significant discussion among developers.

1H AGOIndustry Desk

A federal judge has overturned part of the conviction of former Google software engineer Linwei Ding, who was earlier found guilty of stealing AI trade secrets for two Chinese companies.

9H AGOAI Desk

Security researchers demonstrate how seemingly innocent interview questions can be weaponized to extract sensitive system information and compromise infrastructure. The technique exploits social engineering during technical assessments.

11H AGOIndustry Desk

Attackers hijacked the maintainer account of arrayref, a popular Rust crate, and injected infostealer malware that executed during code compilation. Developers using the poisoned version risked credential and data theft.

12H AGODev Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.