• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Sunday, June 21, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Business

Meta and Yandex Accused of Using Android Loophole to Secretly Track Users

Researchers uncover covert methods linking web activity to user identities through native apps

by Harikrishnan A
June 24, 2025
in Business, Markets, News, Tech, Trending, World
Reading Time: 4 mins read
0
Meta and Yandex Accused of Using Android Loophole to Secretly Track Users
TwitterWhatsappLinkedin

Meta and Yandex are facing intense scrutiny after a team of academic researchers revealed that both tech giants exploited a hidden quirk in Android’s operating system to track users’ online behavior. By quietly using native Android apps to listen for data sent from web browsers on the same device, the companies were reportedly able to match anonymous browsing activity with real user identities—without users ever realizing it.

You might also like

How to Increase Gas Mileage: Small Driving Changes That Save Big at the Pump

Paradigms of Luminance and Chemistry The Definitive OLED vs Mini LED Display Audit

Next-Generation Wireless The Architectural Breakthrough of Wi-Fi 7 Explained

This technique bypassed standard privacy protections that users typically rely on, including clearing cookies, using Incognito Mode, or denying app permissions. The revelations have raised serious concerns about how mobile apps may silently bridge gaps between web and app tracking in ways that users—and even many developers—never anticipated.


The Technical Loophole: How It Worked

The method at the center of the controversy revolves around something called “localhost”—a network interface on your phone that allows apps to communicate with themselves for testing purposes. Ordinarily harmless, localhost becomes problematic when misused.

According to researchers from IMDEA Networks (Spain), Radboud University (Netherlands), and KU Leuven (Belgium), Meta and Yandex designed their Android apps—such as Facebook, Instagram, Yandex Maps, and Yandex Browser—to secretly listen for browser data via these localhost ports. Meanwhile, tracking scripts embedded on thousands of websites—like Meta Pixel and Yandex Metrica—sent browsing data and cookies to those apps in the background.

By combining this browser data with persistent identifiers stored in their native apps—like login credentials or device IDs—the companies could match web activity with real user profiles, essentially erasing the line between app-based and browser-based tracking.


Privacy Protections Rendered Useless

The study found that this technique undermined many common privacy safeguards. Even if a user cleared their cookies, browsed in private mode, or restricted app permissions, the localhost bridge allowed companies to bypass those limitations.

“It breaks the assumption that cookies from one website can’t follow you across the internet,” the researchers explained. “Because these native apps can receive data directly from the browser, they can re-identify you even after you’ve taken steps to stay private.”

The paper names five researchers—Aniketh Girish, Gunes Acar, Narseo Vallina-Rodriguez, Nipuna Weerasekara, and Tim Vlummens—who documented how these tracking tactics were deployed in the real world. The most concerning discovery was that the apps didn’t just gather data from websites owned by Meta or Yandex; they could extract information from any site embedding their analytics scripts.


Meta Hits Pause, Blames Policy Confusion

Following the publication of the research, Meta appeared to backtrack. A spokesperson confirmed that the company had paused the controversial data collection feature and was “in discussions with Google to address a potential miscommunication regarding the application of their policies.”

While Meta did not go into detail, it appears that the company may have overstepped rules in Google’s Play Store, which strictly prohibits covert data harvesting practices.

Researchers confirmed that as of June 3, 2025, the Meta Pixel script was no longer transmitting data to localhost. The underlying code that enabled this type of tracking was also mostly removed, suggesting that Meta is attempting to get ahead of regulatory or platform consequences.


A Step-by-Step Breakdown of Meta’s Method

Here’s how Meta’s system reportedly worked:

  1. A user opens the Facebook or Instagram Android app, which quietly activates a background service.
  2. This service opens network ports, allowing it to listen for incoming messages from the browser.
  3. When the user later visits a website that uses Meta Pixel, the script sends tracking cookies—like the _fbp identifier—to the open ports using WebRTC protocols.
  4. The app then receives this data and forwards it, along with the user’s account details, to Meta servers using GraphQL.
  5. The end result? A direct connection between anonymous browsing activity and the user’s actual Facebook or Instagram account.

Meta is believed to have tested the HTTP version of this approach as early as September 2024. After third-party developers raised red flags in public forums, the company stopped sending data over HTTP—but continued with alternative methods such as WebRTC, STUN, and TURN until the practice ended entirely in mid-2025.


Yandex’s Tracking Tactics Date Back Years

While Meta’s use of this technique was relatively recent, Yandex has reportedly been using similar localhost-based tracking since at least 2017. Yandex’s Android apps, including its Maps and Browser tools, were also found listening on fixed local ports to receive data from its analytics script, Yandex Metrica.

Efforts to contact Yandex for comment were unsuccessful, with emails from reporters reportedly flagged as spam.


Browser Makers Push Back with Fixes

In response to the findings, major browser vendors have started rolling out protections:

  • Google Chrome added code in version 137 (released May 26, 2025) to block the specific WebRTC manipulation used by Meta, though this fix is currently limited to select users.
  • Mozilla Firefox is developing its own safeguards.
  • Brave wasn’t affected by the issue, as it already requires user consent for localhost communication.
  • DuckDuckGo has updated its blocklists to stop Yandex’s tracking scripts from executing.

In addition, the researchers are encouraging Android developers to adopt a new “local network access” permission setting, which would require apps to declare—and get user approval for—any attempt to use localhost for communication. An earlier version of this proposal faced technical setbacks, but the recent revelations could reignite interest.

Tags: androidMetaYandex
Tweet60SendShare17
Previous Post

Intel Leans Into AI and Outsourcing as It Prepares for Sweeping Marketing Overhaul

Next Post

Truth Social Targeted in Cyberattack After U.S. Strikes on Iranian Nuclear Facilities

Harikrishnan A

Aspiring writer. Enjoys gaming, fried chicken and iced tea, preferably all together.

Recommended For You

How to Increase Gas Mileage: Small Driving Changes That Save Big at the Pump

by Samir Gautam
June 21, 2026
0
Fuel prices may rise and fall, but one thing stays constant: drivers want to make every litre go further. The good news is that improving gas mileage does not always require buying a new hybrid or changing cars altogether. A few disciplined habits behind the wheel, along with basic maintenance, can make a noticeable difference over time. For most drivers, the biggest gains come from reducing waste. That means less aggressive acceleration, fewer unnecessary trips, correctly inflated tyres and a car that is mechanically healthy. Smooth Driving Uses Less Fuel The quickest way to burn more fuel is to drive as if every traffic light is a starting grid. Hard acceleration, sharp braking and sudden changes in speed force the engine to work harder and consume more petrol. A smoother approach works better. Accelerate gradually, maintain a steady speed where possible and look ahead to anticipate traffic. If a red light is visible in the distance, easing off the accelerator early is usually more efficient than rushing forward and braking hard at the last moment. Speed also matters. As speeds rise, aerodynamic drag increases and the engine needs more energy to keep the vehicle moving. On highways, staying within a sensible cruising range rather than constantly pushing at high speeds can help reduce fuel consumption. Check Tyre Pressure Regularly Tyres are easy to ignore until something goes wrong, but they play a major role in fuel economy. Under-inflated tyres create more rolling resistance, which means the engine has to use more fuel just to move the car forward. Drivers should check tyre pressure at least once a month, preferably when the tyres are cold. The correct pressure is usually listed on the driver-side door frame or in the owner’s manual. It is important not to use the maximum pressure printed on the tyre sidewall as a target. That figure is not necessarily the recommended setting for the vehicle. The US Environmental Protection Agency notes that under-inflation reduces fuel economy, increases tyre wear and adds to emissions. Stop Carrying Extra Weight A car is not a storage room. Heavy items in the boot may seem harmless, but extra weight makes the engine work harder, especially in city traffic where the vehicle is constantly stopping and starting. Clear out unnecessary tools, boxes, sports gear and other items that have been sitting in the car for weeks. Roof racks and cargo boxes can also hurt mileage by increasing aerodynamic drag. If they are not being used, remove them. This is especially relevant for drivers who spend most of their time on highways, where wind resistance becomes a bigger factor. Keep Up With Maintenance A well-maintained vehicle is usually a more fuel-efficient vehicle. Delayed oil changes, worn spark plugs, clogged air filters, dragging brakes and poor wheel alignment can all affect how efficiently a car runs. Following the manufacturer’s service schedule is the safest route. Use the recommended engine oil grade and get warning lights checked instead of ignoring them. A sudden drop in mileage can be an early sign that something needs attention. The EPA advises motorists to follow their vehicle maintenance schedule and use the recommended motor oil to support better fuel efficiency and safer operation. Combine Trips and Avoid Long Idling Short trips can be surprisingly fuel-hungry because the engine has not had enough time to reach its most efficient operating temperature. Combining errands into one planned route can reduce cold starts, unnecessary kilometres and fuel use. Idling is another quiet fuel drain. If you are waiting for an extended period, switching off the engine can be more sensible than leaving it running. Modern cars do not need long warm-up periods before driving. Start, settle for a few seconds and drive gently. The Bottom Line Better gas mileage is less about one miracle trick and more about consistent habits. Drive smoothly, maintain the right tyre pressure, remove excess weight and service the car on time. These small changes may not feel dramatic on a single trip, but over months of commuting, school runs and highway drives, they can add up to real savings.

Fuel prices may rise and fall, but one thing stays constant: drivers want to make every litre go further. The good news is that improving gas mileage does...

Read more

Paradigms of Luminance and Chemistry The Definitive OLED vs Mini LED Display Audit

by Anochie Esther
June 21, 2026
0
OLED vs Mini LED

The global display and consumer electronics sectors are locked in a historic technological civil war. For years, the gold standard of premium visual performance was dictated by a...

Read more

Next-Generation Wireless The Architectural Breakthrough of Wi-Fi 7 Explained

by Anochie Esther
June 21, 2026
0
Wi-Fi 7 Explained

The global networking landscape is entering a period of massive data scaling. For years, consumer and enterprise spaces managed their growing hardware ecosystems by relying on iterative upgrades...

Read more
Next Post
Challenges Mount for Truth Social as Financial Struggles Emerge: Can Trump’s Social Platform Weather the Storm?

Truth Social Targeted in Cyberattack After U.S. Strikes on Iranian Nuclear Facilities

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?