Browser stealth explained: font fingerprinting
A website can learn which fonts a browser uses by measuring text. Hiding a font list does not stop those checks.
A website can learn which fonts a browser can use without asking for a list. It requests a font, draws a short piece of text, and measures its width. A change in width can reveal that the font is available.
Repeating this across many fonts produces a fingerprint of part of the browser's environment. A site can compare it across visits or check whether it fits the browser's claimed profile. Commercial services use these measurements too: a 2026 study found that Fingerprint Pro collected measurements of rendered text.
How measuring text reveals a font
When a requested font is unavailable, the browser uses a fallback. The text still appears, but its shape and width may change.
A fingerprinting script takes advantage of this behavior. First, it measures a string in a fallback font. Then it requests the same string in a named font, keeping the size and style fixed. If the dimensions change, the named font probably affected the result. FingerprintJS repeats this comparison with several fallbacks and a list of font names.
One matching width is not enough to rule a font out: different fonts can give the same string the same width. Testing several fallbacks makes that coincidence less likely. The result tells the page which fonts it can use, which may differ from the full collection installed on the machine.
Browsers also have a separate, permission-controlled way to list local fonts. Blocking that list leaves ordinary text measurements available.
How text can expose a mismatched profile
Suppose you configure a browser to hide Liberation Serif. A page requests it anyway and measures the result. If the text takes on the hidden font's distinctive width, the browser has exposed something its profile was supposed to conceal.
The page can spot this conflict without knowing who the visitor is. It does need to keep the text and style fixed and account for fonts that are still loading or being substituted.
Changing a returned font list does little to prevent this check if the browser still draws with those fonts. Changing only one measurement method can also leave other ways to check the result.
The font file is only part of the picture. The browser and operating system decide how its outlines become pixels, including how letter edges are smoothed. Even the same font file can produce different pixels across systems, as the Pixel Perfect study explored with web fonts. Some text measurements can differ too; font-metrics research describes variation from rendering settings.
A detector can use this to check a claimed OS: draw the same text with the same supplied font, then compare the result with known configurations. A browser claiming Windows while matching a Linux reference gives it a mismatch to investigate. Browser versions and rendering settings also affect the result, so the reference needs to account for those differences.
This overlaps with canvas fingerprinting: font checks can measure text dimensions, while canvas exposes the actual pixels. Installing Windows fonts on Linux does not automatically make its text look like Windows to these tests.
What protection costs
Limiting the fonts a page can use reduces the combinations it can fingerprint. Firefox's fingerprinting protection can prevent custom fonts outside its default list from being used.
The tradeoff is visible: a replacement font can change line breaks and spacing. It also has its own measurable width. The goal is to expose a less distinctive font environment while keeping pages usable.
Returning random widths has a different cost. Websites use those measurements to position text. If the reported size disagrees with the actual drawing, layouts can break and a consistency check can notice the mismatch.
How Notte handles fonts
Our Chromium runtime chooses a separate font collection when the browser starts, keeping the host machine's fonts from automatically appearing in the browser profile.
Different platform font environments use separate browser pools. Switching a profile label on a running browser would leave its existing font collection in place.
We also check how those fonts are drawn: choosing the right collection alone does not reproduce another system's text rendering. Notte sessions provide this browser setup underneath the automation workflow.
