HELLFIRE https://www.theregister.com/2025/04/07/chrome_135_history_sniffing/ – After 23 years, the privacy plumber has finally arrived to clean up this mess A 23-year-old side-channel attack for spying on people’s web browsing histories will get shut down in the forthcoming Chrome 136, released last Thursday to the Chrome beta channel. At least that’s the hope. The privacy attack, referred to as browser history sniffing, involves reading the color values of web links on a page to see if the linked pages have been visited previously. … When this technique first emerged, this could be done by including a script on the page that iterates through all the links on the page using the browser’s window.getComputedStyle method and records the color used to render them. If a visited page included a link and the visitor’s browser rendered that link in purple, the site owner or script provider would gain access to that information. The attack was mitigated about 15 years ago, though not effectively. Other ways to check link color information beyond the getComputedStyle method were developed. … Regards
Stembolt Chrome 136 fixes 20-year browser history privacy risk Google is fixing a long-standing privacy issue that, for years, enabled websites to determine users’ browsing history through the previously visited links.
HELLFIRE I do believe this was already covered here BTW – https://broadbandbulletin.com/d/2190-faangchrome-to-patch-decades-old-flaw-that-let-sites-peek-at-your-history 🙂 Regards