Not a vulnerabilityNothing is broken into. The probe uses ordinary requests that any page may make, and the software it looks for answers as designed. The objection is that the page is looking at all.
What it is
While the page is open, requests go to the loopback address or to addresses on the visitor's own network, on a fixed set of ports and paths. What answers, how fast it answers, and whether it answers at all tells the sender which software is installed or which devices are present. The result is a characteristic of the machine that no interface exposes and the visitor never offered.
Why it is a separate entry
This is not the page describing itself, it is the page describing the visitor's equipment. The properties found are stable, they say something about the person, and the visitor has no way to see it happen: nothing appears on screen, and blocking it requires knowing it is there.
How it arises
a fraud or device-recognition component checking for locally installed software
a payment or checkout integration probing for a local helper application
a component that enumerates the local network to recognise a returning environment
Not to be confused with
Reading properties the browser exposes about itself, such as fonts or a canvas rendering, is Device fingerprinting. What distinguishes this entry is that the traffic leaves the page and addresses the visitor's own machine or network, which the browser does not present as a property at all.
How to establish it
Requests from the page to a loopback address or to addresses in the visitor's own network range, on a fixed set of ports or paths, present in the capture. Where they occur in every consent mode, that is part of the same observation.
method network-observedQoD 92
Requirements on the measurement
clean profile, and a capture that records requests which never leave the machine; many tools filter loopback traffic by default
capture per consent mode, since the finding is stronger where the probe runs after refusal as well
record the port set and the paths, because that is what makes the purpose identifiable
check the page's own content security policy: a policy that permits the loopback range is corroboration from the site's own configuration
What would refute it
by handThe probe is part of a function the visitor started, such as a local card reader or signing application they chose to use.finding falls
automatedThe traffic is generated by an extension or by software the visitor installed, not by the page.Attribute through the initiator chain, and repeat in a clean profile with no extensions.finding falls
automatedThe probe only runs after an explicit action by the visitor.weakens
by handEvery probe fails and nothing about the result is transmitted onward.Under the terminal-equipment provision the reading itself is the act, so this weakens rather than removes the finding.weakens
Where this plugs into existing processes
The one question that surfaces itDoes anything on this page talk to the visitor's own computer, and on which ports?
In a DPIA, verify this
Verify whether any component addresses the visitor's own machine or network, and in which consent states it does so.
As a procurement clause
No page issues requests to the visitor's loopback address or local network, demonstrated by a capture that includes loopback traffic.
With a complaint, hand over
A capture including loopback requests, the port and path set, the consent state per capture, and the content security policy of the page.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
Legal framing
nl-tw-11-7a
eu-gdpr-6-1-a
eu-gdpr-5-1-c
Objections, and the answer
“It is for fraud prevention.”
That is a purpose, and it has to be stated, limited and justified against a scan of the visitor's own machine. It is not a reason the visitor cannot be told.
“We only check whether a helper application is running.”
Then say so, at the moment it happens, and stop when the visitor refuses. Whether the check is narrow is measurable from the port set in the capture.
“No personal data is collected.”
The provision on terminal equipment attaches to reading from the device, whether or not the result is personal data. And what software someone runs is a characteristic of that person.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0021: Probing the visitor's own device. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0021
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0021, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.