Is there any plausible circumstance in which the navigator userAgent reported by Javascript could be different from the one sent as User-Agent Header.
Part of the reason I am asking is that: I have an app that collects the User Agent from JS to report back to the server. It's not necessary in most legit cases. However, could they actually differ or lie?
navigator.userAgent being 'read only' makes the change unlikely. I am just wondering if a hacker or an extension could in fact do so, on common browsers or a headless browser, for whatever reason.
yes, in case of incomplete user-agent spoofing.
browser addons like
will only change user-agent in http-header, but not in javascript variables
for a [more] complete user-agent spoofing, also change the javascript variables:
// ==UserScript==
// @name Change navigator.userAgent
// @namespace Rob W
// @description Changes navigator.userAgent to IE on IEGallery.com
// @match http://www.iegallery.com/*
// @run-at document-start
// @grant none
// @version 1
// ==/UserScript==
Object.defineProperty(navigator, 'userAgent', {
value: 'Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Trident/6.0)'
});
test pages:
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With