Meta, Yandex Caught Unmasking Android Users; Meta Claims “Miscommunication”

Meta and Yandex quietly fused Android users’ “anonymous” web histories with their logged-in app identities, researchers say—shredding the sandbox walls that are meant to keep mobile apps and browsers in separate lanes.

A joint team from Radboud University, IMDEA Networks, and KU Leuven discovered that the Meta Pixel and Yandex Metrica analytics scripts—embedded in about 5.8 million and 3 million sites, respectively—silently pass cookies from Chrome, Firefox and other Android browsers to Facebook, Instagram and Yandex apps that are listening on hard-coded localhost ports.

Since September 2024 for Meta and as far back as 2017 for Yandex, the trackers have used a rotating toolkit—HTTP requests, WebSockets and a WebRTC trick called SDP munging—to smuggle the cookies to ports on the same device. The native apps immediately pair those web IDs with the user’s persistent account token and relay the match to backend servers, even in Incognito mode or behind a VPN. 

Antimony Resources — sponsored Sponsored · Antimony Resources

With Meta Pixel sitting on roughly one-fifth of the web’s top sites and Android commanding 70% of global handset share, the pool of exposed users runs into the billions. Researchers found the Pixel active on 16,000 EU-based sites alone; Yandex performed similar linking on at least 1,300 properties. 

Google called the scheme “a blatant violation of our security and privacy principles” and says Chrome 137 now blocks the specific WebRTC abuse, with broader Android fixes under review. 

Meta said it has “paused the feature” pending talks with Google about a “miscommunication” over Play Store policies, while Yandex asserted the data “does not collect any sensitive information” and that it is discontinuing the practice. 

Brave and DuckDuckGo already blacklist the relevant localhost calls; Chrome’s patch blocks the current SDP variant; Firefox is still “actively investigating.”


Information for this briefing was found via Ars Technica and the sources mentioned. The author has no securities or affiliations related to this organization. Not a recommendation to buy or sell. Always do additional research and consult a professional before purchasing a security. The author holds no licenses.

Video Articles

Silver Is in a New Price Regime, and the Market Isn’t Used to It | Keith Neumeyer – First Majestic

Agnico Eagle Just Made a Massive Gold Land Grab

A Copper-Gold Deposit Caught the White House’s Attention | Rob McLeod – Cambria Gold

Recommended

Mercado Drills 256 g/t Silver Over 6.5 Metres In First Drill Hole of Inaugural Program

Antimony Resources Drills 4.38% Sb Over 7.05 Metres At Bald Hill In Final Hole Of 2025 Program

Trending

Related News

Did Meta Pause A China Scam Crackdown To Protect Revenue?

Meta Platforms (NASDAQ: META) built an $18.4 billion China ad business in 2024 while internally...

Wednesday, December 17, 2025, 12:54:00 PM

Chinese-Based Baidu Applies for ‘Meta’ Trademark Right After Zuckerberg Changes Facebook Name

It appears that Mark Zuckerberg may soon face some rivalry, after Chinese search engine company...

Wednesday, November 3, 2021, 04:55:00 PM

Meta Turns to Google Chips in Blow to Nvidia’s AI Dominance

Meta Platforms (Nasdaq: META) is negotiating a multibillion-dollar agreement to purchase Google‘s custom artificial intelligence...

Tuesday, November 25, 2025, 11:14:00 AM

Mark Zuckerberg Announces Facebook Will be Changing Name to ‘Meta’

Social media behemoth Facebook (NASDAQ: FB) has decided to completely rebrand itself from the toxicity...

Thursday, October 28, 2021, 04:07:00 PM

Meta’s Policy Changes Prompt High-Profile Lawyer to Quit

Stanford law professor Mark Lemley has quit as Meta‘s (Nasdaq: META) lawyer (or “fired” Meta...

Saturday, January 18, 2025, 03:17:00 PM