A detailed look at how Facebook and Instagram opening links in a custom in-app browser on iOS lets Meta track every interaction, including entering passwords
The iOS Instagram and Facebook app render all third party links and ads within their app using a custom in-app browser.
Felix Krause
Context & Ripple Effects
Meta had already asked Facebook and Instagram users to enable tracking after Apple’s iOS privacy changes, framing that data collection as support for free services in an earlier iOS tracking prompt. The custom browser creates an additional app-controlled layer for observing activity once users follow outbound links.
Facebook and Instagram users opening third-party links or ads on iOS have their interactions measured inside Meta’s custom browser, including sensitive login-field activity.
Meta gains visibility into outbound web activity without sending users directly to a separate browser environment.
Second-order effects
Meta’s browser layer supplements the tracking access it sought through iOS consent prompts, preserving an app-controlled source of interaction signals when users follow links.
The planned Android browser engine would carry the same controlled browsing model into Facebook’s Android experience, increasing pressure on publishers to account for traffic arriving through Meta-managed browsers.
Third-order effects
If Meta continues moving outbound browsing into owned engines across its apps, measurement will increasingly depend on platform-controlled web surfaces rather than on handoffs to users’ default browsers.
The trend: Large consumer platforms are bringing outbound web activity inside proprietary browser layers to retain measurement control across mobile operating systems.
This is really grim, if not entirely unexpected: apparently the Instagram mobile app injects additional JavaScript into every page that's loaded using the in-app embedded browser - here's the tool @KrauseFx built to track changes made to the DOM when loading a page https://twitte…
On Twitter, tap your avatar, then Settings and privacy, then Accessibility, display and languages, then Display, then on the next page, toggle off Use in-app browser. You're welcome https://twitter.com/...
If it weren't for antitrust regulators breathing down their necks I'd be worried that Apple was going to ban the use of WKWebView for browsing and limit in-app browsers to Safari, which would kill my Web Reader feature. (They may mandate some kind of warning alert though) https:/…
If you click a link in your Instagram or Facebook app, Meta (Facebook) actually modifies the pages you're reading so that it can track every single thing you do on those sites. https://twitter.com/...
“The more I think about it, the more I cannot believe webviews with unfettered JavaScript access to third-party websites ever became a legitimate, accepted technology. It's bad for users, and it's bad for websites.” https://twitter.com/...
I have long wondered why, when I click a Twitter link on my iPhone, it opens inside Twitter instead of in a normal browser. Now I know. The answer is evil: https://www.holovaty.com/...
This is more complicated than it looks - all browsers on iOS but Safari are based on WebView. On Android, at least Opera Mini and DuckDuckGo are built on top of WebView. Implementing X-Frame-Options on the WebView level would make those browsers unviable. https://twitter.com/...
Asking the big question “why do we let the in-app webview do that?” ("That" being break our sites, inject JavaScript, steal IP, etc.) @adrianholovaty ties the past to the present. A must-read. https://twitter.com/...
This is a smart idea: Apple and Google should make in-app browsers respect X-Frame-Options: Deny to open a page in the user's chosen web browser. As noted, they have zero commercial incentive to do so... but lots of user experience incentive. What happens when the two conflict? h…
Reminder #1000 that if you're not paying for it, and the organization doesn't have a clear alternative story about how its free thing makes it money, then you're the product https://twitter.com/...
Apple's security argument as to why it can't allow third party browser engines on iOS 🤝 Apple allowing Instagram and Facebook in-app browsers on iOS to inject tracking scripts on any web site https://krausefx.com/...
Why is this a big deal? Instagram & Facebook actively work around the new App Tracking Transparency System which was designed to prevent exactly this kind of abuse, to keep tracking users outside their ecosystem https://twitter.com/...
Apple has built “App-Bound Domains”, which could help avoid this kind of platform abuse, however it's not mandatory yet. Unfortunately, even the iOS Lockdown Mode doesn't prevent Instagram fetching user data from third party websites. https://twitter.com/...
Adrian's proposed solution mirrors mine: headers should allow pages to “punch-out” of sub-standard treatment while we breathlessly await mobile OSes enforcing reasonable, pro-privacy, pro-user, pro-web policies. On second thought, don't hold your breath.
This is a really interesting writeup from @KrauseFx on how the Instagram app subjects users to pervasive tracking and circumvents the privacy protections recently rolled out in iOS. https://krausefx.com/... A few notes/observations 1/x
My first blog post in four years (!) — How the seemingly innocuous “in-app web browsers” on iOS/Android are a really bad thing, and a proposal for how to fix that. With a little web history thrown in. https://www.holovaty.com/...
@katebevan At least on iOS, you can't turn this off for Instagram. Also, Twitter for iOS does NOT track your, they use the recommended SFSafariViewController, which runs in a separate process
If you want an inkling of the reason I'm so upset about “in app browsers”, here's someone else noticing what I've been wittering on about: https://krausefx.com/...
You can turn this off on both Facebook and Twitter. On Facebook, tap the hamburger menu, then tap Settings, then Media (yeah, it's sneakily hidden). Down at the bottom of the next page, tick Links open externally. https://twitter.com/...
Don't know why everyone is sounding so surprised at this. Of *course* Facebook tracks you via its in-app browser. So does Twitter, for that matter. https://twitter.com/...
In case you needed a reminder about why we care so much about OAuth/OIDC flows being used in the system browser and not embedded browsers, Instagram injects their own tracking code in every web page you visit inside Instagram https://krausefx.com/...
The the surprise if absolutely nobody Meta does shady stuff in their in app browser. I really want to know how devs within Meta justify this type of stuff. https://krausefx.com/...
Just to be clear, my screenshots are Android. Not sure what the situation is on iOS; I don't have any Apple devices, tho Felix suggests it's not so egregious on iOS https://twitter.com/...