Breaking
June 6, 2025

Meta Apps Have Been Covertly Tracking Android Users’ Web Activity for Months Jake Peterson | usagoldmines.com

I don’t expect Meta to respect my data or my privacy, but the company continues to surprise me with how low they’re willing to go in the name of data collection. The latest such story comes to us from a report titled “Disclosure: Covert Web-to-App Tracking via Localhost on Android.” In short, Meta and Yandex (a Russian technology company) have been tracking potentially billions of Android users by abusing a security loophole in Android. That loophole allows the companies to access identifying browsing data from your web browser as long as you have their Android apps installed.

How does this tracking work?

As the report explains, Android allows any installed app with internet permissions to access the “loopback address” or localhost, an address a device uses to communicate with itself. As it happens, your web browser also has access to the localhost, which allows JavaScripts embedded on certain websites to connect to Android apps and share browsing data and identifiers.

What are those JavaScripts, you might ask? In this case, that’s Meta Pixel and Yandex Metrica, scripts that let companies track users on their sites. Trackers are an unfortunate part of the modern internet, but Meta Pixel is only supposed to be able to follow you while you browse the web. This loop lets Meta Pixel scripts send your browsing data, cookies, and identifiers back to installed Meta apps like Facebook and Instagram. The same goes for Yandex with its apps like Maps and Browser.

You certainly didn’t sign up for that when you installed Instagram on your Android device. But once you logged in, the next time you visited a website that embedded Meta Pixel, the script beamed your information back to the app. All of a sudden, Meta had identifying browsing data from your web activity, not via the browsing itself, but from the “unrelated” Instagram app.

Chrome, Firefox, and Edge were all affected in these findings. DuckDuckGo blocked some but not all of the domains here, so it was “minimally affected.” Brave does block requests to the localhost if you don’t consent to it, so it did successfully protect users from this tracking.

Researchers say Yandex has been doing this since February of 2017 on HTTP sites, and May of 2018 on HTTPS sites. Meta Pixel, on the other hand, hasn’t been tracking this way for long: It only started September of 2024 for HTTP, and ended that practice in October. It started via Websocket and WebRTC STUN in November, and WebRTC TURN in May.

Website owners apparently complained to Meta starting in September, asking why Meta Pixel communicates with the localhost. As far as researchers could find, Meta never responded.

Researchers make it clear that the type of tracking is possible on iOS, as developers can establish localhost connections and apps can “listen in” too. However, they found no evidence of this tracking on iOS devices, and hypothesize that it has to do with how iOS restricts native apps running in the background.

Meta has officially stopped this tracking

The good news is, as of June 3, researchers say they have not observed Meta Pixel communicating with the localhost. They didn’t say the same for Yandex Metrika, though Yandex told Ars Technica it was “discontinuing the practice.” Ars Technica also reports that Google has opened an investigation into these actions that “blatantly violate our security and privacy principles.”

However, even if Meta has stopped this tracking following the report, the damage could be widespread. As highlighted in the report, estimates put Meta Pixel adoption anywhere from 2.4 million to 5.8 million sites. From here, researchers found that just over 17,000 Meta Pixel sites in the U.S. attempt to connect to the localhost, and over 78% of those do so without any user consent needed, including sites like AP News, Buzzfeed, and The Verge. That’s a lot of websites that could have been sending your data back to your Facebook and Instagram apps. The report features a tool that you can use to look for affected sites, but notes the list is not exhaustive, and absence doesn’t mean the site is safe.

Meta has not replied to my request for comment as of time of publication. However, the company did reportedly provide Ars Technica with the following statement: “We are in discussions with Google to address a potential miscommunication regarding the application of their policies. Upon becoming aware of the concerns, we decided to pause the feature while we work with Google to resolve the issue.”

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Use Your iPhone As a Webcam for Nintendo Switch 2 Tim Hardwick | usagoldmines.com

watchOS 26 to Support These Apple Watch Models Tim Hardwick | usagoldmines.com

M&S CEO directly targeted by hackers demanding ransom payout | usagoldmines.com

Alphabet CEO Sundar Pichai says AI won't lead to job cuts, will be "an accelerator" | usagoldmines....

The iPhone 17 Air could lack a near-essential feature, but I'm not convinced | usagoldmines.com

The iPhone 17 is tipped to come with a MagSafe charging boost – but it might cost you | usagoldmine...

Running Windows on your Mac doesn’t have to suck — this app makes it easy | usagoldmines.com

Get the most out of your Nintendo Switch 2 with these 3 TVs I've picked to pair with it, including o...

Why most companies shouldn’t build their own AI solutions | usagoldmines.com

WordCamp Europe 2025 - all the latest news and updates as they happen | usagoldmines.com

The best monitors: 11 top picks for gaming, 4K, HDR, and more | usagoldmines.com

Luma Labs' new Modify Video tool can reimagine scenes without reshooting erichs211@gmail.com (Eric H...

Hard drive, SSD, or USB flash drive: Which portable storage is right for you? | usagoldmines.com

I use this $18 box to safely plug in all my outdoor smart devices | usagoldmines.com

The best external drives: 9 top picks for portable storage | usagoldmines.com

WWDC 2025: What to Expect From tvOS 26 Juli Clover | usagoldmines.com

Senate response to White House budget for NASA: Keep SLS, nix science Eric Berger | usagoldmines.com

Samsung Slams $150 Off Galaxy Ring With Any Smartwatch Trade Kellen | usagoldmines.com

Mint Mobile Cuts $800 Off a Pixel 9 With 2 Years of Service Kellen | usagoldmines.com

Meta AI's experimental new smart glasses can see everything you do and even tell how you feel about ...

Google's Chrome Browser Gets 'Highest Score Ever' on Speedometer Performance Test Juli Clover | usag...

Apple Watch Control Center May Support Third-Party App Shortcuts in watchOS 26 Juli Clover | usagold...

What NOT to expect at Apple's WWDC 2025 - three things you definitely won't see philip.berne@futuren...

AMD’s RX 9060 XT is a budget beast, if you can find it at MSRP | usagoldmines.com

Stop Using These Recalled Bowflex Adjustable Dumbbells Now Meredith Dietz | usagoldmines.com

Discord CTO says he’s “constantly bringing up enshittification” during meetings Scharon Harding | us...

Why an Apple TV Box Is More Private Than Your Smart TV (but Not Perfect) Justin Pot | usagoldmines.c...

WWDC 2025: All the Rumors About visionOS 26 Juli Clover | usagoldmines.com

Want to run a GeForce RTX 5090 on your ultra-thin laptop? This Thunderbolt 5 eGPU enclosure can make...

What would happen if Trump retaliated against Musk’s companies? Eric Berger | usagoldmines.com

9 menial tasks ChatGPT can handle for you in seconds, saving hours | usagoldmines.com

Free yourself from summer chores with Dreame’s Z1 Pro pool cleaner | usagoldmines.com

Apple's Long-Rumored 'homeOS' Possibly Trademarked Ahead of WWDC Joe Rossignol | usagoldmines.com

Nvidia will sell a special version of its most powerful GPU to China to skirt around US export restr...

Volvo launches the first smart seatbelt that uses sensors to provide the perfect tension | usagoldm...

Nvidia RTX 5060/5060 Ti review: You can have “affordable” or “future-proof.” Pick one. Andrew Cunnin...

Google releases updated Gemini 2.5 Pro, says it’s the “most intelligent model yet” Ryan Whitwam | us...

How Insurance Companies Use Drones to Raise Your Rates (and What to Do About It) Jeff Somers | usago...

PlayStation Adds Apple Pay Support for PS4 and PS5 Store Purchases Juli Clover | usagoldmines.com

Amazon Has Low Prices on Apple Pencil Pro ($99) and AirTag 4-Pack ($74.99) Mitchel Broussard | usago...

Forget the RTX 5090, this monster is Nvidia's fastest GPU ever manufactured - but it will cost you a...

Microsoft’s Surface Pro pricing is a ripoff | usagoldmines.com

Upcoming Windows 11 feature aims to smartly extend laptop battery life | usagoldmines.com

Fanttik Aero X review: This robotic pool cleaner is an underwater monster | usagoldmines.com

Samsung Brings Sleep Apnea Feature on Galaxy Watch to Total of 70 Markets Tim | usagoldmines.com

Here’s the Crazy Arc Pulse Case for Galaxy S25 Ultra Kellen | usagoldmines.com

These Smart Tech Gadgets Make Great Father’s Day Gifts Amanda Blum | usagoldmines.com

Peloton Is Launching Its Own Resale Platform, and It'll Be Much Better Than Facebook Marketplace Lin...

My Favorite Adjustable Dumbbell Workout Only Takes 15 Minutes Meredith Dietz | usagoldmines.com

Here's How Many iPhones Are Running iOS 18 Juli Clover | usagoldmines.com

'We created a new Airbnb' – here's what the app's big redesign means for how you travel and where yo...

Sony announces Project Defiant, its first-ever wireless fight stick controller designed for PS5 and ...

Have an iPhone but not iOS 18 yet? You’re in the minority jacob.krol@futurenet.com (Jacob Krol) | us...

Reddit sues Anthropic over AI scraping that retained users’ deleted posts Ashley Belanger | usagoldm...

Nintendo warns Switch 2 GameChat users: “Your chat is recorded” Kyle Orland | usagoldmines.com

Peloton Is Launching Its Own Resale Platform, and It'll Be Much Better Than Facebook Marketplace Lin...

Apple Watch Gets Snapchat App Juli Clover | usagoldmines.com

MPA presses for VPNs to have a role in anti-piracy row in Europe chiara.castro@futurenet.com (Chiara...

Hisense's new portable 4K laser projector takes the fight to LG and Samsung, with bright, colorful i...

Alien: Earth finally has an official trailer, and it teases threats even bigger than the dreaded Xen...

PS5’s Thief VR could make me love my PSVR 2 again | usagoldmines.com

Fake DocuSign and Gitcode sites are tricking victims into downloading malware - here's what you need...

Fujifilm teaser suggests the rumored X-E5 is imminent – and it looks like an affordable X100VI alter...

What solar? What wind? Texas data centers build their own gas power plants Dylan Baddour, Arcelia Ma...

Microsoft is adding a simpler text editor than Notepad to Windows 11 soon | usagoldmines.com

Google Drive gets AI-generated summaries of changes made to files | usagoldmines.com

Save $300 on Acer’s productivity laptop with extra-long battery life | usagoldmines.com

I Ranked This Tiny, Cheap Robot Vacuum Higher Than a Dyson That Costs Three Times More Amanda Blum |...

This Self-Propelled Lawn Mower Is at Its Lowest Price Ever Naima Karp | usagoldmines.com

Apple Watch Gets One Crucial Fitness Metric Wrong, Researchers Say Hartley Charlton | usagoldmines.c...

HomePod Turns 8: Here's When to Expect New Models Joe Rossignol | usagoldmines.com

FBI warns Play ransomware hackers have hit nearly a thousand US firms | usagoldmines.com

Stephen Graham's powerful drama Adolescence has performed so well for Netflix that it's beaten Stran...

Cisco warns over worrying security flaws in ISE affecting AWS, Azure cloud deployments - here's what...

Final Fantasy Tactics remaster officially announced with a Nintendo Switch 2 version confirmed for S...

Summer Game Fest 2025 live build-up: where to watch and everything you need to know before the Geoff...

“In 10 years, all bets are off”—Anthropic CEO opposes decadelong freeze on state AI laws Benj Edward...

Xenomorphs are back and bad as ever in Alien: Earth trailer Jennifer Ouellette | usagoldmines.com

Disney’s free streaming ‘perks’ are just insulting | usagoldmines.com

Get these ultra-fast USB-C cables on sale, now 2 for only $12 | usagoldmines.com

Five Shows to Watch While You Wait for the Next Season of 'Hacks' Stephen Johnson | usagoldmines.com

Someone Built an AI Agent for the iPhone Before Apple Could David Nield | usagoldmines.com

iPhone Users Say Mail App Suddenly Showing Blank Screen on iOS 18.5 Joe Rossignol | usagoldmines.com

Amazon Takes Up to $65 Off 11th Gen iPad, Starting at $299 Mitchel Broussard | usagoldmines.com

Apple Arcade Adding Four More Games, Including Angry Birds Bounce Joe Rossignol | usagoldmines.com

More than 3 million records, 12TB of data exposed in major app builder breach | usagoldmines.com

Silent Hill f gets an official release date and a creepy PS5 gameplay trailer | usagoldmines.com

NYT Connections hints and answers for Friday, June 6 (game #726) | usagoldmines.com

NYT Strands hints and answers for Friday, June 6 (game #460) | usagoldmines.com

Quordle hints and answers for Friday, June 6 (game #1229) | usagoldmines.com

Can UK businesses balance AI ambitions with sustainability obligations? | usagoldmines.com

Your Amazon delivery person might soon be a robot, which isn't as terrible as it sounds lance.ulanof...

AI is growing up: how to guide it from experimental child to trusted enterprise adult | usagoldmine...

The best free VPNs: 5 no-cost top picks | usagoldmines.com

Want stronger online security? Think like Gen Z | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

This Anker docking station doubles as a monitor stand and it’s 20% off | usagoldmines.com

Alienware’s elegant wireless gaming mouse is down to its best-ever price | usagoldmines.com

This Tool for Runners Quickly Measures the Incline of Any Hill Beth Skwarecki | usagoldmines.com

The Google Pixel Tablet Is $140 Off Right Now Pradershika Sharma | usagoldmines.com