Chrome 148's Math.tanh Bug Leaks Your OS to Trackers
13 Jul 2026
A quiet V8 change just created a new browser fingerprinting vector
A change buried in Chromium's V8 JavaScript engine has turned a basic math function into an operating system identifier. Since Chrome 148, calling Math.tanh() no longer returns the same result across platforms — and the differences are consistent enough to reveal whether a visitor is on Linux, macOS, or Windows.
What changed
The root cause is a V8 commit (c1486295ae5) that replaced the cross-platform fdlibm math library with the standard library's std::tanh. That switch first shipped in V8 14.8.57, corresponding to Chrome 148. Because std::tanh calls into OS-native math libraries — glibc on Linux, libsystem_m on macOS, and UCRT on Windows — the output now depends on which OS is running the browser.
The practical effect: Math.tanh(0.8) returns three distinct floating-point values depending on OS:
- Linux (glibc): 0.6640367702678491
- macOS (libsystem_m): 0.664036770267849
- Windows (UCRT): 0.6640367702678489
These differences are tiny — in the last one or two decimal digits — but they're deterministic, meaning a script can reliably use them to distinguish OSes. Chrome 147 and earlier do not exhibit this leak; it's confirmed present in Chrome 148, 149, and 150.
An added wrinkle: on Apple Silicon, the scalar libsystem_m routine and the vector routines in Apple's Accelerate framework diverge from each other on 10 to 89 percent of a million tested inputs, depending on the function — meaning even within a single OS, the choice of math routine matters.
Why this matters for fingerprinting
Browser fingerprinting scripts already probe device and rendering quirks to build unique visitor profiles. This tanh discrepancy adds a new, low-cost signal: a single JavaScript call now leaks OS identity without needing user-agent strings, canvas rendering, or other more commonly-blocked techniques.
The report flags three specific risks:
- General fingerprinting risk: any site can use
Math.tanhoutput differences to determine a visitor's OS across Linux, macOS, and Windows. - Privacy tool exposure: anti-fingerprinting and privacy-focused browsers may need updates to normalize
Math.tanhoutputs, or they'll leak OS info despite other protections. - Detection of spoofed environments: fingerprinting systems trying to detect fake or emulated browsers may catch mismatches when a spoofed environment doesn't produce the OS-correct tanh output.
What's still unclear
Several open questions remain, per the report:
- Whether Chrome or V8 maintainers plan to patch or mitigate this vector.
- Whether other
Mathfunctions beyondtanhare similarly affected. - How this technique compares in reliability to existing fingerprinting methods.
- Whether other Chromium-based browsers (Edge, Brave, etc.) inherit the same behavior.
- The full list of affected functions and their exact divergence rates on Apple Silicon beyond the reported 10–89% range.
Why founders should care
For founders building in privacy, anti-detect browsers, or fraud/bot detection, this is likely to matter in a few concrete ways:
- If you build or rely on privacy-preserving browser tools, this OS leak could undermine anonymity claims until
Math.tanhoutputs are normalized across platforms — a fix your product may need to ship proactively. - If you're in fraud detection or bot mitigation, this signal could plausibly be incorporated into detection stacks, though its long-term reliability is uncertain since it depends on Chrome's internal math library choices, which could change again.
- If your product emulates or spoofs browser environments (for testing, automation, or evasion), this change likely increases the odds of detection, and you may need updated techniques to account for it.
- More broadly, this is a reminder that underlying engine changes in V8/Chromium can introduce fingerprinting side effects with no warning — teams in the privacy and security space should monitor upstream commits, not just headline feature releases, since seemingly unrelated performance or library changes can quietly become detection vectors.
The opportunities cut both ways: privacy vendors have a clear incentive to patch this quickly, while anti-fraud vendors have a plausible new signal to test — at least until browser vendors standardize math implementations across platforms and close the gap.