Skip to main content

The browser can render a sound no one hears.

A page can build the same synthetic audio graph in every browser, render it entirely in memory, and measure the resulting numbers. Small implementation differences can become a repeatable signal inside a broader browser fingerprint—without using your microphone or speakers.

Microphone
Not required
Audible sound
None
Primary surface
Web Audio API
Result
Numeric render
offline audio graphspeaker output: none
The picture is illustrative. The live demo below renders and measures a real local Web Audio graph.

Render the same graph in this browser.

This demonstration uses your browser’s real OfflineAudioContext. The graph runs locally, never requests microphone permission, never plays through the speakers, and sends no result to 404 Privacy. Run it twice to test repeatability in this session.

Web Audio testReady to render locally
Rendered sample windowwaiting for input
triangle oscillatordynamics compressoroffline buffer
local digest—— —— ——SHA-256 prefix of rendered Float32 samples
Sample rate
—
Frames
—
Peak
—
RMS
—
Runs
0
Session match
Run twice

A matching result demonstrates repeatability here, not global uniqueness. Other browsers and devices may share the same output.

Audio fingerprinting is not microphone fingerprinting.

The word audio makes this technique sound like eavesdropping. The common Web Audio test is different: the page generates a known signal, processes it in memory, and reads the buffer it created. It measures computation, not the room around you.

Audio rendering

Synthetic signal

Input
generated math
Permission
none
What it measures
browser output
Microphone capture

Real-world sound

Input
microphone
Permission
required
What it captures
acoustic input

The fingerprint is the measured output, not the tone.

Every browser receives the same instructions. The observable is the long numeric buffer produced after those instructions pass through the browser’s audio implementation.

  1. 01

    Oscillator

    triangle · 10 kHz

    The page creates a known synthetic input. No recording, media file, or microphone is required.

  2. 02

    Compressor

    threshold · knee · ratio

    A DynamicsCompressorNode applies nonlinear processing that gives the browser more arithmetic to perform.

  3. 03

    Offline renderer

    1 channel · 44.1 kHz

    OfflineAudioContext computes the graph into memory instead of sending it to the speakers.

  4. 04

    AudioBuffer

    5,000 float samples

    The resulting samples can be read as numbers, summarized, serialized, and compared.

  5. 05

    Digest

    repeatable short ID

    A hash turns a long sequence of tiny values into a compact label that is easy to store alongside other signals.

simplified-browser-test.js
const context = new OfflineAudioContext(1, 5000, 44100);
const tone = context.createOscillator();
const compressor = context.createDynamicsCompressor();

tone.type = 'triangle';
tone.frequency.value = 10000;
tone.connect(compressor).connect(context.destination);
tone.start(0);

const buffer = await context.startRendering();
const samples = buffer.getChannelData(0);

A digest makes tiny numerical changes easy to compare.

Two rendered buffers can look identical as waveforms and still differ in low-order digits. Hashing does not make the signal more unique; it compresses the comparison. One changed byte can produce a completely different-looking digest.

browser A… −0.08988945 · 0.01219763 · 0.10492118 …
browser B… −0.08988941 · 0.01219763 · 0.10492118 …
digest A7D2A 91CE
digest B3F80 2B14
Illustrative numbers. Real collectors choose their own graph, sample window, normalization, and summary method.

Repeatable does not automatically mean unique.

Audio output can be stable enough to recognize a browser environment while still being shared by many people. A 2021 study collected Web Audio results from 2,093 users but found only 95 distinct fingerprints. The signal was not highly diverse on its own; it still added information when combined with other browser attributes.

2,093 study participants95 distinct audio results
one shared audio resultuseful as one signal—not a person’s name

Storage and network resets do not replace the audio implementation.

ActionLikely resultWhy
Clear cookiesUsually unchanged

The test rebuilds its result from Web Audio processing instead of reading a stored identifier.

Open a private windowOften unchanged

Private mode isolates local state but usually keeps the same browser engine and audio implementation.

Change IP or use a VPNUnrelated to the render

The network path changes; the offline audio graph still runs inside the browser.

Update or switch browsersMay change

Different engines and releases can implement audio processing or floating-point paths differently.

Change OS or deviceMay change

The surrounding software stack and implementation environment can affect the numeric output.

Enable broad fingerprinting protectionCan standardize or alter it

A privacy mode may return shared results, add controlled variation, or restrict the surface.

The useful goal is a shared answer, not a stranger one.

Blocking Web Audio entirely can break legitimate tools. Privacy-oriented browsers instead have to balance compatibility with making the result less stable or less distinguishing.

01

Standardize

Return the same effective result across a larger group so one browser is harder to distinguish.

02

Alter carefully

Controlled variation can reduce repeatability, but inconsistent defenses can become a new fingerprint.

03

Protect the whole profile

Audio matters most beside canvas, WebGL, fonts, display, headers, and network evidence.