/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A detailed look at how Facebook and Instagram opening links in a custom in-app browser on iOS lets Meta track every interaction, including entering passwords

The iOS Instagram and Facebook app render all third party links and ads within their app using a custom in-app browser.

Felix Krause

Context & Ripple Effects

Meta had already asked Facebook and Instagram users to enable tracking after Apple’s iOS privacy changes, framing that data collection as support for free services in an earlier iOS tracking prompt. The custom browser creates an additional app-controlled layer for observing activity once users follow outbound links.

The pattern extends beyond iOS: Meta later outlined a Chromium-based in-app browser for Facebook on Android, making browser control a cross-platform product choice rather than an isolated implementation detail.

First-order effects

  • Facebook and Instagram users opening third-party links or ads on iOS have their interactions measured inside Meta’s custom browser, including sensitive login-field activity.
  • Meta gains visibility into outbound web activity without sending users directly to a separate browser environment.

Second-order effects

  • Meta’s browser layer supplements the tracking access it sought through iOS consent prompts, preserving an app-controlled source of interaction signals when users follow links.
  • The planned Android browser engine would carry the same controlled browsing model into Facebook’s Android experience, increasing pressure on publishers to account for traffic arriving through Meta-managed browsers.

Third-order effects

  • If Meta continues moving outbound browsing into owned engines across its apps, measurement will increasingly depend on platform-controlled web surfaces rather than on handoffs to users’ default browsers.

The trend: Large consumer platforms are bringing outbound web activity inside proprietary browser layers to retain measurement control across mobile operating systems.

Discussion

  • @krausefx Felix Krause on x
    💥 New Post: Instagram & Facebook tracks everything you do on any website in their in-app browser https://krausefx.com/... https://twitter.com/...
  • @simonw Simon Willison on x
    This is really grim, if not entirely unexpected: apparently the Instagram mobile app injects additional JavaScript into every page that's loaded using the in-app embedded browser - here's the tool @KrauseFx built to track changes made to the DOM when loading a page https://twitte…
  • @katebevan Kate Bevan on x
    On Twitter, tap your avatar, then Settings and privacy, then Accessibility, display and languages, then Display, then on the next page, toggle off Use in-app browser. You're welcome https://twitter.com/...
  • @elkmovie Michael Love on x
    If it weren't for antitrust regulators breathing down their necks I'd be worried that Apple was going to ban the use of WKWebView for browsing and limit in-app browsers to Safari, which would kill my Web Reader feature. (They may mandate some kind of warning alert though) https:/…
  • @aulia Aulia Masna on x
    Crafty yet sleazy behavior from Meta, here. Should push links to Safari all the time to avoid this. https://twitter.com/...
  • @anildash Anil on x
    If you click a link in your Instagram or Facebook app, Meta (Facebook) actually modifies the pages you're reading so that it can track every single thing you do on those sites. https://twitter.com/...
  • @drbarnard David Barnard on x
    “The more I think about it, the more I cannot believe webviews with unfettered JavaScript access to third-party websites ever became a legitimate, accepted technology. It's bad for users, and it's bad for websites.” https://twitter.com/...
  • @froomkin @froomkin on x
    I have long wondered why, when I click a Twitter link on my iPhone, it opens inside Twitter instead of in a normal browser. Now I know. The answer is evil: https://www.holovaty.com/...
  • @andreban André Bandarra on x
    This is more complicated than it looks - all browsers on iOS but Safari are based on WebView. On Android, at least Opera Mini and DuckDuckGo are built on top of WebView. Implementing X-Frame-Options on the WebView level would make those browsers unviable. https://twitter.com/...
  • @jbrodsky Jay Brodsky on x
    Asking the big question “why do we let the in-app webview do that?” ("That" being break our sites, inject JavaScript, steal IP, etc.) @adrianholovaty ties the past to the present. A must-read. https://twitter.com/...
  • @sil Stuart Langridge on x
    This is a smart idea: Apple and Google should make in-app browsers respect X-Frame-Options: Deny to open a page in the user's chosen web browser. As noted, they have zero commercial incentive to do so... but lots of user experience incentive. What happens when the two conflict? h…
  • @choldgraf Chris Holdgraf on x
    Reminder #1000 that if you're not paying for it, and the organization doesn't have a clear alternative story about how its free thing makes it money, then you're the product https://twitter.com/...
  • @adrianholovaty Adrian Holovaty on x
    This is appalling behavior by Instagram and Facebook. It's time to do something about it. https://twitter.com/...
  • @hhariri Hadi Hariri on x
    If there's anything Facebook has taught me, it's that no matter what you do, you'll get away with it. Time and time again. https://krausefx.com/...
  • @zachleat Zach Leatherman on x
    Apple's security argument as to why it can't allow third party browser engines on iOS 🤝 Apple allowing Instagram and Facebook in-app browsers on iOS to inject tracking scripts on any web site https://krausefx.com/...
  • @krausefx Felix Krause on x
    Why is this a big deal? Instagram & Facebook actively work around the new App Tracking Transparency System which was designed to prevent exactly this kind of abuse, to keep tracking users outside their ecosystem https://twitter.com/...
  • @krausefx Felix Krause on x
    Apple has built “App-Bound Domains”, which could help avoid this kind of platform abuse, however it's not mandatory yet. Unfortunately, even the iOS Lockdown Mode doesn't prevent Instagram fetching user data from third party websites. https://twitter.com/...
  • @slightlylate Alex Russell on x
    Adrian's proposed solution mirrors mine: headers should allow pages to “punch-out” of sub-standard treatment while we breathlessly await mobile OSes enforcing reasonable, pro-privacy, pro-user, pro-web policies. On second thought, don't hold your breath.
  • @funnymonkey Bill Fitzgerald on x
    This is a really interesting writeup from @KrauseFx on how the Instagram app subjects users to pervasive tracking and circumvents the privacy protections recently rolled out in iOS. https://krausefx.com/... A few notes/observations 1/x
  • @adrianholovaty Adrian Holovaty on x
    My first blog post in four years (!) — How the seemingly innocuous “in-app web browsers” on iOS/Android are a really bad thing, and a proposal for how to fix that. With a little web history thrown in. https://www.holovaty.com/...
  • @krausefx Felix Krause on x
    @katebevan At least on iOS, you can't turn this off for Instagram. Also, Twitter for iOS does NOT track your, they use the recommended SFSafariViewController, which runs in a separate process
  • @slightlylate Alex Russell on x
    If you want an inkling of the reason I'm so upset about “in app browsers”, here's someone else noticing what I've been wittering on about: https://krausefx.com/...
  • @katebevan @katebevan on x
    You can turn this off on both Facebook and Twitter. On Facebook, tap the hamburger menu, then tap Settings, then Media (yeah, it's sneakily hidden). Down at the bottom of the next page, tick Links open externally. https://twitter.com/...
  • @katebevan @katebevan on x
    Don't know why everyone is sounding so surprised at this. Of *course* Facebook tracks you via its in-app browser. So does Twitter, for that matter. https://twitter.com/...
  • @aaronpk Aaron Parecki on x
    In case you needed a reminder about why we care so much about OAuth/OIDC flows being used in the system browser and not embedded browsers, Instagram injects their own tracking code in every web page you visit inside Instagram https://krausefx.com/...
  • @mitsuhiko Armin Ronacher on x
    The the surprise if absolutely nobody Meta does shady stuff in their in app browser. I really want to know how devs within Meta justify this type of stuff. https://krausefx.com/...
  • @katebevan @katebevan on x
    Just to be clear, my screenshots are Android. Not sure what the situation is on iOS; I don't have any Apple devices, tho Felix suggests it's not so egregious on iOS https://twitter.com/...