
DEF CON 33 - Escaping the Privacy Sandbox wClientside Deanonymization Attacks - Eugene Lim
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 34:37
Revised Summary: Escaping Google's Privacy Sandbox
The presentation "Escaping the Privacy Sandbox with Client Side Deanonymization Attacks" by Eugene Lim (Space Raccoon) demonstrates critical vulnerabilities in Google's Privacy Sandbox that enable user deanonymization and bypassing of privacy protections, revealing fundamental tensions between advertising functionality and user privacy.
Context: Google developed Privacy Sandbox as a privacy-preserving replacement for third-party cookies, which are being phased out due to privacy concerns. Despite Google recently delaying the third-party cookie phase-out, Privacy Sandbox remains active in Chrome and Chromium-based browsers and is widely used by advertising platforms.
Key Vulnerabilities Discovered:
1. Attribution Reporting API Bypass of SafeFrame
The Attribution Reporting API, designed to track conversions without revealing personal data, contains a critical vulnerability through its "transitional debug reports" feature. Originally intended as a temporary debugging mechanism, these debug reports remain active despite third-party cookies not being deprecated as planned.
The vulnerability occurs because these debug reports leak top-level site information even when referral policies explicitly prevent this (e.g., with no-referrer policies). This effectively bypasses SafeFrame protections—a hardened iframe standard developed by the Interactive Advertising Bureau to isolate ads and prevent data leakage. By purchasing ads through Google's platform, attackers can deliberately trigger malformed attribution responses that leak the publisher website information to advertisers.
2. Destination Hijacking Attack in Google DoubleClick
The researcher discovered that Google DoubleClick Ads automatically injects two additional "debug conversion domains" into every ad served across their network. By purchasing these unregistered domains for a minimal cost, the researcher could track user behavior through the at
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So this talk is escaping the privacy sandbox with client side deaniza dean anonymization attacks. So if this is the wrong talk u this is your time to kind of change but otherwise thank you for staying with me and uh let's have a good 45 minutes. So a little bit about me. Um I'm Eugene Lim. I go by Space Raccoon online and I'm from Singapore. Uh it took about 15 16 hours to get here and uh it's currently I think 7:30 a.m. in Singapore. So let's see if I can uh make it. Uh in my day job, I do application security for a small organization of about 200 people. So I focus on cyber security, application security. Um but outside of my day job, I love to do vulnerability research. Um I kind of touch everything from hardware to software to web technologies. Uh one of my most recent pieces of resear…