This issue was addressed through improved state management. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A maliciously crafted webpage may be able to fingerprint the user.
No PoCs from references.
- https://github.com/Joe12387/Joe12387
- https://github.com/Joe12387/browser-fingerprinting-resistance-research
- https://github.com/Joe12387/safari-canvas-fingerprinting-exploit