no stylesheet is injecting custom properties into every page
Every probed custom property, and an invented control name, resolve to the empty string on the document's root element.
What a detector infers
A deployed commercial agent reads six CSS custom properties from the document's root element and reports true when four or more of them resolve to anything. No ordinary page declares those names. They are theming variables that a particular browser build writes into the root element of every page it renders, so a non-empty value is that build identifying itself through the style system rather than through anything a fingerprint would capture.
The assertion here generalises past those specific names and does not depend on knowing which product they belong to: on a clean browser, a custom property nobody declared resolves to the empty string, always.
So the probed set is checked together with a control name invented for this audit that could not plausibly be defined anywhere — and if the control comes back non-empty, the computed style is not answering honestly about what is declared, which is a different and worse finding than any particular variable being set. The reason to care is how cheap this is for the other side.
One getComputedStyle call and a handful of property reads: no timing, no rendering, no permission prompt, nothing that looks like fingerprinting at all. It identifies a build directly instead of inferring it, which makes it strictly better than a fingerprint for anyone who can use it.
How to resolve it
Do not inject styling into pages the browser did not author. Variables set on the root element are readable from any page in a single call, with no permission involved — among the cheapest ways to identify a build, and one that bypasses the fingerprint entirely.
Nearby checks in Automation surface
- No controller code crossed the main-world canary
main-world-executionAn early DOM canary records main-world calls, but page code and extensions can also call it, so this is contextual. - No exposed Puppeteer / Playwright binding
exposed-binding-leaksExposed functions leave Playwright/Puppeteer registries, prefixes, source text, or __installed markers. - Content Security Policy is enforced
csp-bypassThe audit excludes data: scripts. Execution despite script-src is direct CSP-bypass behavior. - the browser will not resolve a filesystem path the page invented
synthesized-path-entry-sandboxThis row does not measure a fingerprint. It measures whether the browser will help a page enumerate what is installed on the machine, and it… - window.chrome present for a Chrome UA
chrome-objectThis is a cross-check, not a probe of window.chrome's contents: it first decides whether the browser claims to be Chrome (a Chrome/ token in… - window.chrome.* helpers are native (not JS stubs)
chrome-native-stubsWhere the previous check asks whether window.chrome exists, this one asks whether its members are genuine. - window.external is shaped the way the engine generates it
window-external-shapeA deployed commercial agent lists the absence of this object among its own named failure messages, which means it treats window.external… - no notifications-permission headless bug
permissions-notification-bugTwo independent APIs describe the same underlying notification permission: navigator.permissions.query({name:'notifications'}) returns a…
Clearcote is a browser built for fingerprint coherence
It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.
This audit takes no position on how Clearcote scores on Automation surface checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.
See the other checks in Automation surface — the family injected-root-custom-properties belongs to.
