Researchers Expose How Meta and Yandex Linked Android Browsing Data to User Identities
Researchers have uncovered a significant privacy breach in which tracking codes embedded by Meta (Facebook and Instagram) and Russia-based Yandex de-anonymize Android users’ web browsing histories. This is achieved by exploiting the legitimate communication between web browsers and native mobile apps using local ports on Android devices. Meta and Yandex’s analytics tools—Meta Pixel and Yandex Metrica—send data from browser-based tracking cookies to native apps through WebRTC and other protocols, bypassing sandboxing and privacy protections in Android and Chromium-based browsers.
This covert tracking allows the companies to associate anonymous browsing behavior with specific user identities, even in private browsing modes. While Meta began this technique in September 2024, Yandex has used similar methods since 2017. These actions violate Android’s privacy expectations and Google Play policies. In response, browsers like DuckDuckGo, Brave, and Chrome have implemented partial mitigations to block such communications.
However, experts warn that these fixes are fragile and can be circumvented. The researchers advocate for platform-level changes to Android and browser architectures to restrict uncontrolled access to local ports. Google and Mozilla are investigating the abuses, and both Meta and Yandex claim they are either pausing or ceasing the practice.
