Author: Rimsha Zafar
August 7, 2025

Flash Cookies: The Complete Guide to Local Shared Objects

For over a decade, a tracking technology quietly collected user data without appearing in any browser settings menu. Flash cookies stored information through Adobe Flash Player, operating entirely outside the controls that users relied on to manage their privacy online.

 

This guide covers everything you need to know about flash cookies. It explains what they are, how they differ from regular browser cookies, the privacy and security risks they introduced, the lawsuits they triggered, and the compliance lessons businesses must take from their history.

What Are Flash Cookies

Flash cookies are a form of persistent data storage tied to Adobe Flash Player. Understanding their mechanics is essential for grasping why they became one of the most controversial tracking technologies.

Definition of Flash Cookies

Flash cookies, also known as Local Shared Objects (LSOs), are small data files created and stored by Adobe Flash Player on a user’s computer. They function similarly to standard HTTP cookies but operate independently of the browser’s cookie management system entirely.

 

Adobe Systems introduced Local Shared Objects in 2002 as part of the Flash Player platform. Their original purpose was to save user preferences, game progress, and playback settings for Flash-based multimedia content across browsing sessions on websites.

How Flash Cookies Store Data

Flash cookies use a binary file format with the .sol extension. They are stored in a dedicated directory managed by Adobe Flash Player, entirely separate from the folders where browsers keep their standard cookies and cached data files.

 

On Windows, these files typically reside under the AppData\Roaming\Macromedia\Flash Player directory. On macOS, they are found within the Library/Preferences/Macromedia/Flash Player folder. This separation made them invisible to standard browser privacy tools.

Storage Capacity and Limits

Each Flash cookie could store up to 100KB of structured data per domain. This is roughly 25 times the 4KB limit of a standard HTTP cookie. The extra capacity allowed websites to save complex user profiles and detailed session information.

 

Unlike standard cookies that store simple text strings, flash cookies supported structured data types including objects, arrays, and binary elements. This made them far more versatile for developers building interactive Flash-based applications and multimedia content online.

Flash Cookies vs Browser Cookies

The differences between Flash cookies and regular browser cookies go well beyond storage size. Their behaviour, visibility, and deletion methods are fundamentally different, which is exactly what made flash cookies so problematic for users.

Storage Location and Visibility

Browser cookies are stored within the browser’s own data directory and can be viewed, managed, or deleted through built-in settings. Flash cookies are stored in a system-level directory controlled by Adobe Flash Player, completely outside the browser’s reach.

 

This separation meant that even users who were diligent about managing their cookie policy settings and clearing browser data regularly had no visibility into the flash cookie data being quietly collected on their devices.

Persistence After Deletion

When users cleared their browser cookies, flash cookies remained completely untouched on their systems. This persistence allowed websites to continue identifying and tracking users even after they had taken deliberate steps to protect their own privacy.

 

Some websites exploited this persistence through a technique called cookie respawning. They stored the same unique identifier in both a browser cookie and a flash cookie. If the user deleted the browser cookie, the flash cookie restored it automatically.

Comparison Table: Flash Cookies vs HTTP Cookies vs HTML5 Local Storage

Storage Comparison Table
Feature Flash Cookies (LSOs) HTTP Cookies HTML5 Local Storage
Storage Limit 100KB per domain 4KB per domain 5 to 10MB per domain
Storage Location Adobe Flash Player directory Browser cookie folder Browser local storage
Browser Visibility Not visible in browser settings Visible and manageable Visible in developer tools
Persistence Survives browser cookie deletion Deleted with browser clear Persists until manually cleared
Cross-Browser Tracking Yes, system-level storage No, browser-specific No, browser-specific
Expiration No automatic expiration Configurable expiry date No automatic expiration
User Control Required separate Flash settings Full browser control Accessible via browser settings
Current Status Obsolete since 2021 Still widely used Still widely used

How Websites Used Flash Cookies

Websites deployed flash cookies for purposes ranging from legitimate functionality to covert surveillance. Understanding these use cases reveals why they attracted both widespread adoption and eventually serious regulatory scrutiny.

Advertising and Behavioural Tracking

Advertising networks used flash cookies to build persistent user profiles across multiple websites. Because LSOs survived browser resets and worked across different browsers on the same device, they offered advertisers an almost indestructible tracking mechanism.

 

This type of cross-site tracking directly conflicted with emerging user consent standards. Users were being profiled without their knowledge, let alone their explicit agreement, violating the fundamental principles of informed and lawful data collection.

Content Personalisation and Preferences

Streaming platforms and gaming websites used flash cookies to store playback positions, volume settings, and game progress. These were legitimate uses that genuinely improved user experience, but they operated without transparent disclosure about the underlying data storage.

 

The problem was not the functionality itself but rather the total absence of transparency. Users had no way to know what data was being stored, how long it persisted, or which third parties could access the information saved within flash cookie files.

Session Management and Analytics

Some websites used flash cookies to maintain login sessions and gather analytics data about user behaviour. This included tracking page views, click patterns, time spent on content, and navigation paths across multiple visits to the same website.

 

While session management is a standard practice, using flash cookies for this purpose meant the collected data was far more persistent and harder to control than data gathered through conventional browser-based cookie mechanisms available at the time.

Privacy and Security Risks of Flash Cookies

Flash cookies introduced privacy and security vulnerabilities that went far beyond what standard browser cookies could create. These risks eventually triggered lawsuits, regulatory action, and a fundamental shift in tracking technology standards.

Cross-Browser Tracking Without Consent

Because flash cookies were stored at the system level rather than within individual browsers, they could track a single user across Chrome, Firefox, Safari, and Internet Explorer simultaneously. No other cookie technology at the time had this capability.

 

This cross-browser tracking happened without user awareness or agreement. There was no notification, no consent prompt, and no easy way to discover that a website was using Flash Player to maintain persistent identifiers across every browser on the device.

Cookie Respawning and Zombie Cookies

The most alarming practice was cookie respawning, where a website used flash cookie data to recreate deleted browser cookies. This technique earned flash cookies the name zombie cookies because they effectively returned after users tried to remove them. Businesses working with an opt-in vs opt-out model found this practice fundamentally at odds with giving users genuine choice over their tracking preferences.

 

Samy Kamkar’s Evercookie project in 2010 demonstrated just how far respawning could go. His proof-of-concept tool stored tracking identifiers across multiple storage mechanisms including flash cookies, HTML5 storage, and browser history, making complete removal nearly impossible.

Security Vulnerabilities in Flash Player

Flash Player itself was plagued by security flaws throughout its entire lifespan. Attackers exploited these vulnerabilities to execute malicious scripts, hijack user sessions, and gain unauthorised access to systems through crafted flash content and manipulated cookie files.

 

The combination of privacy invasion and security risk made Flash cookies a dual threat. Users faced not only unwanted tracking but also potential exposure to malware, data theft, and cross-site scripting attacks enabled by the Flash Player architecture.

Lawsuits and Legal Consequences

The covert nature of Flash cookie tracking eventually triggered significant legal action in the United States. These cases set important precedents for how courts and regulators view hidden tracking technologies and the requirement for user consent.

Quantcast and Clearspring Class Action

In 2010, multiple class action lawsuits were filed against Quantcast and Clearspring Technologies for using flash cookies to respawn deleted browser cookies. Plaintiffs argued this violated the Computer Fraud and Abuse Act and the Electronic Communications Privacy Act.

 

The case was settled for approximately 2.5 million dollars, with most funds directed to privacy advocacy groups and educational institutions. The settlement required the defendants to stop using flash cookies to recreate tracking data without obtaining informed user consent.

Hulu, Disney, and Other Cases

Publishers including Hulu, Disney subsidiary ABC, MTV, JibJab, and Scribd were also named in the flash cookie lawsuits. These companies were required to provide better mechanisms for users to opt out of tracking as part of the overall settlement terms.

 

The legal outcomes demonstrated that businesses could not claim ignorance about third-party tracking technologies embedded within their platforms. Courts made clear that website operators bear full responsibility for all data collection happening on their websites.

What the Settlements Changed

These lawsuits forced the technology industry to acknowledge that stealth tracking constituted a deceptive practice. They accelerated the development of privacy regulations and contributed directly to the momentum behind the ePrivacy Directive and eventually the GDPR.

 

The cases also highlighted the importance of protecting sensitive personal information collected through any tracking mechanism. Businesses learnt that failing to disclose all data collection methods carries real and significant financial and reputational consequences.

Flash Cookies and Data Protection Laws

Modern data protection laws address the exact types of practices that flash cookies enabled. Understanding how these regulations apply helps businesses avoid repeating the same compliance failures with any newer tracking technologies.

Flash Cookies Under GDPR

The General Data Protection Regulation (GDPR) requires explicit, informed consent before any non-essential tracking data is collected from users. Flash cookies would clearly fall within scope as they stored personal identifiers without user knowledge, transparency, or any consent mechanism.

 

GDPR also mandates that businesses explain clearly what data they collect, why they collect it, and how long they store it. The opacity of flash cookie storage made compliance with these transparency requirements practically impossible for any website using this technology.

The ePrivacy Directive and Cookie Consent

The ePrivacy Directive, often called the EU cookie law, specifically addresses the storage of information on user devices. Under this directive, any technology that stores data on a user’s device requires prior informed consent, with the sole exception of strictly necessary functionality.

 

Flash cookies would have required explicit consent under the ePrivacy Directive. Their silent, system-level storage without any user notification or opt-in mechanism was the exact type of behaviour this directive was designed to prevent across the European Union.

CCPA and the Right to Know

The California Consumer Privacy Act (CCPA) gives residents the right to know what personal information businesses collect about them. Businesses using flash cookies would have been required to disclose this data collection in their privacy policies and provide deletion mechanisms.

 

Under the CCPA and the updated California Privacy Rights Act, consumers also have the right to opt out of the sale or sharing of their personal information. Flash cookie respawning would directly violate this right by restoring tracking data after a user opted out.

How to Detect and Remove Flash Cookies

Removing flash cookies required steps that went well beyond standard browser maintenance. Users needed to navigate obscure settings panels or manually locate hidden files on their systems to fully eliminate all stored tracking data.

Adobe Flash Player Settings Manager

Adobe provided an online Settings Manager that allowed users to view and delete stored Flash cookies. This tool displayed a list of websites that had created Local Shared Objects and offered controls to remove them individually or clear all stored data.

 

The problem was discoverability. Very few users knew the Settings Manager existed, and it was hosted on Adobe’s website rather than built into the browser. This design choice effectively kept flash cookie management entirely out of reach for the vast majority of users.

Manual Deletion From the File System

Users could also delete Flash cookies by navigating to the file system directories where .sol files were stored. On Windows, these files were located under AppData\Roaming\Macromedia\Flash Player. On macOS, they were in the Library/Preferences/Macromedia folder.

 

This approach required technical knowledge that most users simply did not possess. The hidden nature of these directories, combined with the unfamiliar file extension, made manual deletion impractical as a mainstream privacy measure for everyday internet users.

Browser Extensions and Privacy Tools

Third-party browser extensions such as BetterPrivacy for Firefox eventually emerged to automate flash cookie deletion. These tools scanned for and removed Local Shared Objects during regular browser cleanup routines. Today, consent management platforms offer businesses a comprehensive way to handle all forms of tracking and data collection with proper user consent.

 

Modern browsers no longer support Flash Player, which means new flash cookies cannot be created. However, businesses that operated websites during the Flash era should still audit their systems to ensure no legacy .sol files or dormant Flash-based tracking scripts remain active.

Flash Cookies vs Supercookies and Evercookies

Flash cookies belong to a broader family of persistent tracking mechanisms often grouped under the terms supercookies and evercookies. Understanding how they relate helps anyone working in privacy compliance or digital marketing.

What Are Supercookies

Supercookie is an umbrella term for any tracking mechanism that stores data outside the standard browser cookie storage. Flash cookies are one type of supercookie. Others include HSTS supercookies, ISP-injected tracking headers, and advanced browser fingerprinting techniques.

 

The defining characteristic of supercookies is their resistance to standard deletion methods. Unlike regular cookies that users can clear through browser settings, supercookies persist through normal cleanup routines and often require specialised tools or technical knowledge to remove.

What Are Evercookies

Evercookies are a specific type of supercookie designed to be virtually impossible to delete. Created by security researcher Samy Kamkar in 2010, evercookie technology stores tracking data across multiple storage mechanisms simultaneously, including flash cookies, HTML5 storage, and browser cache.

 

When any single storage location is cleared, the evercookie recreates itself from copies stored elsewhere. This takes the cookie respawning concept used by flash cookies to an extreme degree. Businesses collecting zero-party data ethically should understand these techniques to ensure their own practices remain fully transparent and lawful.

Key Differences at a Glance

Cookie Comparison Table
Feature Flash Cookies Supercookies Evercookies
Storage Method Adobe Flash Player .sol files Various non-standard locations Multiple simultaneous locations
Respawning Yes, from Flash to browser Depends on type Yes, from any surviving copy
Deletion Difficulty Moderate, requires Flash settings Varies by type Extremely difficult to remove
Current Relevance Obsolete since 2021 Some types still active Proof of concept, rarely deployed
Primary Use Tracking and preferences Tracking and identification Demonstrates tracking persistence

Are Flash Cookies Still Used Today

Adobe Flash Player reached end of life in December 2020, and all major browsers removed support by early 2021. However, whether flash cookies are truly gone deserves a more careful answer for compliance professionals and businesses.

Adobe Flash Player End of Life Timeline

Adobe announced in July 2017 that Flash Player would reach end of life on 31 December 2020. This gave the industry over three years to migrate away from Flash-based content and remove all dependencies on Flash cookie technology from their platforms.

 

Apple Safari removed Flash support in September 2020. Google Chrome followed in January 2021 with version 88. Firefox dropped support in version 85, also released in January 2021. Microsoft Edge removed Flash in version 88 during the same month.

Legacy Risks That Still Exist

While new Flash cookies cannot be created, legacy .sol files may still exist on user devices and business servers. Archived Flash content, outdated third-party codebases, and neglected marketing tools could still contain dormant Flash cookie tracking mechanisms from past years.

 

Businesses that operated websites during the Flash era should conduct thorough audits of their systems. Any remaining Flash-based tracking scripts, .sol files, or references to Macromedia storage directories should be identified and removed to ensure full regulatory compliance.

Modern Tracking Alternatives

Today, web tracking relies on browser cookies, HTML5 local storage, server-side tagging, and fingerprinting techniques. Unlike flash cookies, most modern tracking methods are designed to work within the framework of consent management platforms and data protection regulations.

 

Consent-based approaches such as server-side tagging and privacy-first analytics have replaced the covert tracking methods that flash cookies represented. These modern solutions prioritise transparency, user control, and regulatory compliance by design.

Wrapping Up

Flash cookies represent a cautionary chapter in digital privacy. They showed that any tracking technology operating without transparency, user control, and informed consent will eventually face legal consequences and public backlash. Businesses today must apply these lessons to every tracking method they deploy, ensuring that compliance and user trust remain at the centre of their data practices.

Simplify Consent Management With Seers AI

Managing consent across cookies, local storage, and modern tracking technologies does not have to be complicated. Seers AI gives your business an AI-powered consent management platform that automates compliance, builds user trust, and keeps you ahead of evolving privacy regulations.

START FREE TODAY

Frequently Asked Questions (FAQs)

What is the difference between flash cookies and regular browser cookies?

Flash cookies are stored by Adobe Flash Player in a system-level directory, while regular browser cookies are stored within the browser itself. Flash cookies could hold up to 100KB of data per domain compared to 4KB for standard cookies. They were invisible to browser cookie managers and survived normal browser clearing routines, which made them significantly harder for users to detect and delete.

Why were flash cookies considered a privacy threat?

Flash cookies tracked users across multiple browsers on the same device without their knowledge or consent. They persisted after browser cookies were deleted and could respawn deleted browser cookies through a technique called cookie respawning. This meant users who actively tried to protect their privacy were still being tracked, directly undermining their choices and violating the principles of informed data collection.

Can flash cookies still track me today?

No, flash cookies cannot track you today because Adobe Flash Player reached end of life in December 2020 and all major browsers removed Flash support by early 2021. However, if you used the internet during the Flash era, legacy .sol files may still exist on your computer. Running a search for .sol files in the Macromedia or Flash Player directories on your system can help identify and remove any remaining traces.

In 2010, class action lawsuits were filed against Quantcast, Clearspring Technologies, and several publishers including Hulu and Disney subsidiary ABC. The plaintiffs alleged violations of the Computer Fraud and Abuse Act and the Electronic Communications Privacy Act. The cases resulted in a settlement of approximately 2.5 million dollars, with funds directed to privacy advocacy groups and educational institutions focused on consumer data protection.

How did flash cookies respawn deleted browser cookies?

Websites stored the same unique tracking identifier in both a regular browser cookie and a flash cookie simultaneously. When a user cleared their browser cookies, the website script checked whether the flash cookie still existed. If it did, the script used the identifier stored in the flash cookie to recreate the deleted browser cookie, effectively restoring the tracking capability without the user’s knowledge or permission.

What are the differences between flash cookies, supercookies, and evercookies?

Flash cookies are a specific type of supercookie that used Adobe Flash Player for data storage. Supercookies are a broader term covering any tracking mechanism stored outside standard browser cookie storage. Evercookies are an extreme version that stores tracking data across multiple storage mechanisms simultaneously, including flash cookies, HTML5 storage, and browser cache, making them nearly impossible to fully remove from a device.

Would flash cookies violate GDPR if they were still in use?

Yes, flash cookies would clearly violate GDPR requirements. The regulation mandates explicit, informed consent before collecting personal data through tracking technologies. Flash cookies operated silently without user notification, lacked any consent mechanism, and stored data in locations users could not easily access or manage. These characteristics directly contradict the transparency, lawful basis, and user rights provisions that GDPR establishes.

What tracking technologies replaced flash cookies after Flash Player was discontinued?

Modern tracking relies on browser cookies with proper consent management, HTML5 local storage, server-side tagging, and privacy-first analytics platforms. Unlike flash cookies, these technologies are designed to comply with data protection laws like GDPR and CCPA. Consent management platforms now automate the process of obtaining, recording, and managing user consent across all tracking technologies on a website.

Businesses should search their web servers and content delivery networks for any remaining .sol files or references to Macromedia storage paths. They should also review third-party scripts and plugins for Flash-based dependencies. Any marketing tools, analytics platforms, or content management systems that were active during the Flash era should be checked for dormant Flash cookie code that could pose compliance risks.

What lessons from the Flash cookies era apply to modern compliance strategies?

The key lesson is that any tracking technology must operate with full transparency, informed user consent, and accessible deletion mechanisms. Businesses must disclose all data collection methods clearly, provide genuine control over tracking preferences, and avoid any practice that undermines user choices. Regular compliance audits, a properly configured consent management platform, and privacy-by-design principles are essential safeguards.

 

Rimsha Zafar

Rimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.

ORCIDResearchGateGoogle ScholarLinkedIn