Advertorial
Tivoroz
Finland Edition · Digital Privacy Desk

The Favicon Exploit: How Your Browser's Tab Icons Are Used as Supercookies

Clearing your history feels like a clean break. Cookies gone, cache emptied, private window open, VPN switched on — a fresh start. The favicon exploit is built to survive every one of those actions. It hides your identity in the one place your "clear browsing data" button was never designed to touch: the tiny cache that stores the little logos in your browser tabs. There is no cookie to delete, because the identifier is written in something you never think about.

Browser tab bar with small favicon icons representing hidden tracking identifiers
Favicons look decorative — but a caching quirk lets them double as a persistent identifier.
  • Cache-level defense
  • Runs in the background
  • Normal favicons unaffected

What This Article Covers

This article covers four things: why the tracking industry went hunting for storage you cannot easily reach, how a favicon Supercookie is written and read back in four steps, why routine privacy hygiene leaves it perfectly intact, and where Total Adblock's Deep Cache Sanitization can realistically step in. As with the rest of this series, the limits of that defense are stated plainly, without claiming more than it can do.

The search for the "undeletable" tracker

Two forces closed in on the ordinary tracking cookie at once. Privacy regulations forced consent banners onto nearly every site, and browsers put a one-click "clear history" button within easy reach. Between the two, a standard cookie became something a motivated user could refuse or wipe in seconds. For an industry that depends on recognizing you across visits, that was a problem.

So the search shifted. If a user can delete anything they know about, the obvious move is to store the identifier somewhere they don't know about — ideally somewhere the "clear data" button skips entirely. The goal stopped being a better cookie and became a hiding place that ordinary cleanup misses.

The favicon cache turned out to fit that description almost perfectly. It sits at the top of your screen, it exists for a legitimate reason, and for years the standard privacy controls left it alone. That combination is exactly what a persistent tracker needs.

How the favicon Supercookie operates

The trick relies on a specialized storage area often called the F-Cache, short for favicon cache. Favicons are the small icons shown in tabs and bookmarks, and browsers cache them aggressively so they appear instantly. Crucially, this cache has historically run on its own, separate from the browsing history most cleanup tools target. That independence is the whole opening.

Here is how a tracker turns that cache into a stable identifier.

  1. Step 1 — The subdomain matrix

    When you land on a compromised site, a hidden script quietly routes your browser through a rapid series of invisible subdomains — say a1.tracker.com, a2.tracker.com, and so on. You see nothing; the redirects happen in the background in a fraction of a second.

  2. Step 2 — The binary ID generation

    For some of those subdomains the tracker serves a real favicon. For others it deliberately returns a "404 Not Found." Each subdomain becomes a single slot that is either filled or empty by design.

  3. Step 3 — The F-Cache storage

    Your browser dutifully records which subdomains produced an icon and which failed. "Icon present" reads as a 1, "icon missing" reads as a 0, and across the whole matrix that pattern forms a unique binary sequence — a number written into your favicon cache, one slot at a time.

  4. Step 4 — The persistent recall

    Days later you clear your cookies, empty your standard cache, and turn on a VPN. Then you return to any site on the same tracking network. The script walks the same subdomains and checks which favicons your browser still remembers. It reads back your binary sequence, recognizes you instantly, and staples that identity to a fresh batch of tracking cookies. You never left; you just thought you had.

The unsettling part is that no single step is an exploit. Serving an icon is normal. Returning a 404 is normal. Caching favicons for speed is normal. The identifier lives in the arrangement, not in any one request.

Why "clearing your history" fails

This method is effective precisely because it sidesteps the habits people rely on to feel private. Three specifics explain why.

Cache isolation. In most major browsers, "Clear Browsing Data" targets standard HTTP cookies and local storage. The favicon cache has historically been treated as a separate performance store and left untouched, so your binary Supercookie sails through the cleanup completely intact.

No consent required. Favicons are classified as basic interface elements a site needs to function, so they load without waiting for the cookie consent banner. The Supercookie can be written before you have clicked a single button on the privacy popup — there is no moment of permission to withhold.

Cross-browser and device-level reach. More advanced variants lean on how the operating system handles desktop shortcuts and icon storage, which can carry an identifier across a switch from, say, Chrome to Safari or Edge. What began as a per-browser trick edges toward a persistent fingerprint tied to the device itself.

"The tools are not broken. They are guarding a door this threat does not walk through."

The pattern matches the earlier articles in this series: a cleanup routine that empties cookies and cache has nothing to remove when the identifier is written into a cache it was never told to clear.

Breaking the Supercookie chain

Reduce the problem to its core and one dependency stands out. Writing the identifier requires that rapid, sequential march through a matrix of subdomains, each one probed for a present-or-missing icon. That pattern does not look like a browser loading one ordinary favicon for one site. It looks like a machine being interrogated bit by bit — and that distinctive behavior is something a defense can watch for. The weakness moves from a cache you cannot easily clear to a network pattern that is hard to disguise.

That is the layer Total Adblock's Deep Cache Sanitization and Request Filtering operates on. Rather than trusting that a favicon request is always innocent, it watches the requests made for site assets and treats the cache as something to govern, not something to fill without question.

The logic runs as a short chain:

The Defense Chain

  • The network requests for favicons and similar assets are monitored, so the rapid, sequential pinging characteristic of binary ID generation stands out from a normal single-icon load.
  • When that signature appears, the requests are intercepted before the full pattern can be written into the F-Cache.
  • Third-party domains are restricted from leaning on the favicon cache for cross-site identification, so a decorative interface element cannot quietly double as a persistent tracker.
Editor's Note — What It Does, and Doesn't

The boundary deserves the same honesty as the earlier pieces. This filtering acts on requests from this point forward. It disrupts the writing and reading of the Supercookie pattern going forward; it does not reach back and scrub a binary sequence that a tracker already planted and read during an earlier session before the defense was in place, and it does not change how your operating system stores desktop-shortcut icons outside the browser. Its role is to close the road ahead — and against a technique whose entire advantage is being written before you notice and read back after you think you're clean, that forward road is exactly the one that counts. Because the filtering targets the abnormal probing pattern rather than ordinary favicon loads, the icons on the sites you actually use keep appearing normally.

Reclaim your browser state

The uncomfortable lesson of the favicon Supercookie is that the privacy routine most people trust — clear the history, open a private window, switch on a VPN — quietly assumes every identifier lives somewhere that routine reaches. This one does not. Nothing looks wrong, no banner asks permission, and the icon that fingerprints you is the same harmless logo you have seen in a thousand tabs.

Diagram-style illustration of subdomains and cache slots used to encode a tracking identifier
Each subdomain acts as one slot in a binary sequence — present or missing, one or zero.

The practical response is not to distrust every favicon or to abandon private browsing, which still does useful work. It is to stop treating "I cleared my history" as proof of a clean slate, and to add a layer that watches for the abnormal request pattern a Supercookie needs before it can be written or read. Governing how your browser handles its own asset caches closes a gap that basic cleanup was never built to see.

Let Total Adblock's Deep Cache Sanitization and Request Filtering intercept the probing pattern behind favicon tracking, so the little icons in your tabs stay decoration and never become an identity you can't erase.

How It Works


  1. Install

    Add the App to your browser in a few clicks.

  2. Set Up

    Grant permission to monitor site asset requests.

  3. Activate

    Turn on Deep Cache Sanitization & Request Filtering.

  4. Use the App

    Browse normally — the App watches for the pattern in the background.

What Users Notice


Improved Privacy

Fewer chances for cross-site scripts to quietly re-identify your browser after you thought you'd started fresh.

Steadier Browsing

Abnormal, rapid-fire background requests get intercepted instead of silently probing your cache.

Normal Site Appearance

Ordinary favicon loading is left alone, so the sites you use look exactly as expected.

Frequently Asked Questions


What is a favicon Supercookie?

It is a tracking identifier written into your browser's favicon cache instead of a standard cookie. Because that cache has historically been treated as a separate performance store, it can survive routine steps like clearing cookies, emptying cache, and browsing privately.

Why doesn't clearing my browsing history remove it?

Most "Clear Browsing Data" tools target standard cookies and local storage. The favicon cache sits outside that scope in many browsers, so an identifier written there is not automatically wiped when you clear your history.

Does a VPN protect me from this kind of tracking?

A VPN changes your network address, but it does not clear or govern your browser's favicon cache. If the identifier is already stored there, a VPN alone does not remove it.

How does Total Adblock's Deep Cache Sanitization work?

It monitors network requests for favicons and similar assets, watching for the rapid, sequential probing pattern that binary ID generation produces, and intercepts that pattern before it can be fully written to the cache.

Will this feature block normal favicons from loading?

No. The filtering is designed to target the abnormal, sequential probing signature rather than ordinary single-icon requests, so the icons on the sites you actually use continue to appear normally.

Can this remove an identifier that was already planted?

No. The filtering acts on requests going forward. It does not reach back and erase a binary sequence that was written and read during an earlier session before the defense was active.

Does this affect how my operating system stores shortcut icons?

No. The App governs browser-level favicon requests. It does not change how your operating system stores or caches icons for desktop shortcuts outside the browser.

Should I stop using private browsing mode?

No. Private browsing still does useful work for other kinds of tracking. The recommendation is to add a layer that watches for abnormal cache request patterns, not to abandon existing habits.

Total Adblock

Stop the Icon That Recognizes You

Add a layer that watches for the abnormal request patterns favicon tracking depends on, so your privacy routine covers a gap that basic cleanup was never built to see.

Secure Your Browser Architecture with Total Adblock

Results may vary depending on individual circumstances and product usage.

This page is a paid advertorial. It contains sponsored content and affiliate links intended to promote the App. The publisher may receive compensation for actions taken through links on this page. Content is provided for informational purposes and should not be considered independent editorial review.