/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A detailed look at how Facebook and Instagram for iOS open links with a custom in-app browser, letting Meta track every interaction including entering passwords

How the seemingly innocuous “in-app web browsers” on iOS/Android are a really bad thing, and a proposal for how to fix that. With a little web history thrown in. https://www.holovaty.com/... @katebevan : You can turn this off on both Facebook and Twitter. On Facebook, tap the hamburger menu, then tap Settings, then Media (yeah, it's sneakily hidden). Down at the bottom of the next page, tick Links open externally. https://twitter.com/... @katebevan : Don't know why everyone is sounding so surprised at this. Of *course* Facebook tracks you via its in-app browser. So does Twitter, for that matter. https://twitter.com/... Alex Russell / @slightlylate : If you want an inkling of the reason I'm so upset about “in app browsers”, here's someone else noticing what I've been wittering on about: https://krausefx.com/... Aaron Parecki / @aaronpk : In case you needed a reminder about why we care so much about OAuth/OIDC flows being used in the system browser and not embedded browsers, Instagram injects their own tracking code in every web page you visit inside Instagram https://krausefx.com/... Armin Ronacher / @mitsuhiko : The the surprise if absolutely nobody Meta does shady stuff in their in app browser. I really want to know how devs within Meta justify this type of stuff. https://krausefx.com/... Felix Krause / @krausefx : @katebevan At least on iOS, you can't turn this off for Instagram. Also, Twitter for iOS does NOT track your, they use the recommended SFSafariViewController, which runs in a separate process @katebevan : Just to be clear, my screenshots are Android. Not sure what the situation is on iOS; I don't have any Apple devices, tho Felix suggests it's not so egregious on iOS https://twitter.com/...

Felix Krause

Context & Ripple Effects

Apple’s iOS 14 privacy changes had already pushed Facebook and Instagram to ask users to permit tracking in prompts framed around keeping their services free; the apps’ tracking-permission messaging after iOS 14 provides the backdrop for scrutiny of data collection inside links opened from their feeds.

The distinction is not uniform across Meta’s apps: Facebook exposes an external-link setting, while Instagram does not. Later coverage of Meta building a Chromium-based browser engine for Facebook on Android indicates that control of the link-opening layer is becoming a product choice across platforms.

First-order effects

  • Meta can observe interactions within Facebook and Instagram’s embedded iOS browsing flow; Instagram’s reported page-level tracking-code injection makes that exposure extend to activity on sites users visit from the app.
  • Facebook users can route links to an external browser through a setting, while Instagram users on iOS lack an equivalent opt-out.

Second-order effects

  • Publishers and login providers whose pages open inside Instagram must treat Meta’s embedded browser as an additional intermediary around reader and account interactions.
  • Meta’s planned Android browser engine gives Facebook a route to retain control over link handling beyond iOS, while Twitter’s use of a separate-process Safari view marks a different implementation choice.

Third-order effects

  • If app-owned browsers continue to replace handoffs to the system browser, privacy choice will increasingly depend on each app’s disclosure and exit controls rather than on the browser protections users selected.
  • The resulting divide between Facebook’s external-link option and Instagram’s lack of one points toward platform-level governance of embedded webviews becoming a durable consumer-protection issue.

The trend: Social platforms are treating the browser opened from their apps as a controlled data and product surface, rather than a neutral handoff to the user’s chosen browser.

Discussion

  • @krausefx Felix Krause on x
    💥 New Post: Instagram & Facebook tracks everything you do on any website in their in-app browser https://krausefx.com/... https://twitter.com/...
  • @simonw Simon Willison on x
    This is really grim, if not entirely unexpected: apparently the Instagram mobile app injects additional JavaScript into every page that's loaded using the in-app embedded browser - here's the tool @KrauseFx built to track changes made to the DOM when loading a page https://twitte…
  • @katebevan Kate Bevan on x
    On Twitter, tap your avatar, then Settings and privacy, then Accessibility, display and languages, then Display, then on the next page, toggle off Use in-app browser. You're welcome https://twitter.com/...
  • @elkmovie Michael Love on x
    If it weren't for antitrust regulators breathing down their necks I'd be worried that Apple was going to ban the use of WKWebView for browsing and limit in-app browsers to Safari, which would kill my Web Reader feature. (They may mandate some kind of warning alert though) https:/…
  • @aulia Aulia Masna on x
    Crafty yet sleazy behavior from Meta, here. Should push links to Safari all the time to avoid this. https://twitter.com/...
  • @anildash Anil on x
    If you click a link in your Instagram or Facebook app, Meta (Facebook) actually modifies the pages you're reading so that it can track every single thing you do on those sites. https://twitter.com/...
  • @drbarnard David Barnard on x
    “The more I think about it, the more I cannot believe webviews with unfettered JavaScript access to third-party websites ever became a legitimate, accepted technology. It's bad for users, and it's bad for websites.” https://twitter.com/...
  • @froomkin @froomkin on x
    I have long wondered why, when I click a Twitter link on my iPhone, it opens inside Twitter instead of in a normal browser. Now I know. The answer is evil: https://www.holovaty.com/...
  • @andreban André Bandarra on x
    This is more complicated than it looks - all browsers on iOS but Safari are based on WebView. On Android, at least Opera Mini and DuckDuckGo are built on top of WebView. Implementing X-Frame-Options on the WebView level would make those browsers unviable. https://twitter.com/...
  • @jbrodsky Jay Brodsky on x
    Asking the big question “why do we let the in-app webview do that?” ("That" being break our sites, inject JavaScript, steal IP, etc.) @adrianholovaty ties the past to the present. A must-read. https://twitter.com/...
  • @sil Stuart Langridge on x
    This is a smart idea: Apple and Google should make in-app browsers respect X-Frame-Options: Deny to open a page in the user's chosen web browser. As noted, they have zero commercial incentive to do so... but lots of user experience incentive. What happens when the two conflict? h…
  • @choldgraf Chris Holdgraf on x
    Reminder #1000 that if you're not paying for it, and the organization doesn't have a clear alternative story about how its free thing makes it money, then you're the product https://twitter.com/...
  • @adrianholovaty Adrian Holovaty on x
    This is appalling behavior by Instagram and Facebook. It's time to do something about it. https://twitter.com/...
  • @hhariri Hadi Hariri on x
    If there's anything Facebook has taught me, it's that no matter what you do, you'll get away with it. Time and time again. https://krausefx.com/...
  • @zachleat Zach Leatherman on x
    Apple's security argument as to why it can't allow third party browser engines on iOS 🤝 Apple allowing Instagram and Facebook in-app browsers on iOS to inject tracking scripts on any web site https://krausefx.com/...
  • @krausefx Felix Krause on x
    Why is this a big deal? Instagram & Facebook actively work around the new App Tracking Transparency System which was designed to prevent exactly this kind of abuse, to keep tracking users outside their ecosystem https://twitter.com/...
  • @krausefx Felix Krause on x
    Apple has built “App-Bound Domains”, which could help avoid this kind of platform abuse, however it's not mandatory yet. Unfortunately, even the iOS Lockdown Mode doesn't prevent Instagram fetching user data from third party websites. https://twitter.com/...
  • @slightlylate Alex Russell on x
    Adrian's proposed solution mirrors mine: headers should allow pages to “punch-out” of sub-standard treatment while we breathlessly await mobile OSes enforcing reasonable, pro-privacy, pro-user, pro-web policies. On second thought, don't hold your breath.
  • @funnymonkey Bill Fitzgerald on x
    This is a really interesting writeup from @KrauseFx on how the Instagram app subjects users to pervasive tracking and circumvents the privacy protections recently rolled out in iOS. https://krausefx.com/... A few notes/observations 1/x
  • @adrianholovaty Adrian Holovaty on x
    My first blog post in four years (!) — How the seemingly innocuous “in-app web browsers” on iOS/Android are a really bad thing, and a proposal for how to fix that. With a little web history thrown in. https://www.holovaty.com/...
  • @krausefx Felix Krause on x
    @katebevan At least on iOS, you can't turn this off for Instagram. Also, Twitter for iOS does NOT track your, they use the recommended SFSafariViewController, which runs in a separate process
  • @slightlylate Alex Russell on x
    If you want an inkling of the reason I'm so upset about “in app browsers”, here's someone else noticing what I've been wittering on about: https://krausefx.com/...
  • @katebevan @katebevan on x
    You can turn this off on both Facebook and Twitter. On Facebook, tap the hamburger menu, then tap Settings, then Media (yeah, it's sneakily hidden). Down at the bottom of the next page, tick Links open externally. https://twitter.com/...
  • @katebevan @katebevan on x
    Don't know why everyone is sounding so surprised at this. Of *course* Facebook tracks you via its in-app browser. So does Twitter, for that matter. https://twitter.com/...
  • @aaronpk Aaron Parecki on x
    In case you needed a reminder about why we care so much about OAuth/OIDC flows being used in the system browser and not embedded browsers, Instagram injects their own tracking code in every web page you visit inside Instagram https://krausefx.com/...
  • @mitsuhiko Armin Ronacher on x
    The the surprise if absolutely nobody Meta does shady stuff in their in app browser. I really want to know how devs within Meta justify this type of stuff. https://krausefx.com/...
  • @katebevan @katebevan on x
    Just to be clear, my screenshots are Android. Not sure what the situation is on iOS; I don't have any Apple devices, tho Felix suggests it's not so egregious on iOS https://twitter.com/...
  • @krausefx Felix Krause on x
    Meta has provided additional information, which I included in the publication. The article is still correct, however it's not the Meta Pixel that gets injected, but a script called “pcm.js” https://krausefx.com/... https://twitter.com/... https://twitter.com/...
  • @openwebadvocacy @openwebadvocacy on x
    In-App Browsers should not be allowed to subvert a user's choice of browser. Both Apple and Google should enforce this from an OS level. OWA is advocating for users to be given control over what happens when they tap a link no matter what the app is. https://www.theguardian.com/ …
  • @slightlylate Alex Russell on x
    Folks, this in-app browser thing really isn't complicated: An app that isn't a browser, but steals traffic from browsers for web content it doesn't serve, is shady af.
  • @counternotions Kontra on x
    This is completely blown out of proportion: How else could Facebook stand up to Apple for small businesses everywhere?! ↓ https://twitter.com/...
  • @benadida Ben Adida on x
    4/ I sincerely hope both Apple and Google bring the hammer down on FB/IG unless they disclose to users exactly what they're doing. This is serious.
  • @migueldeicaza Miguel de Icaza on x
    @mrwcjoughin The engine is WebKit, but there are three way of using it: WKWebView (what Facebook is using to inject spyware), SFSafariViewController (they can't inject it, had plenty of real features of the full safari and JIT) and launching the standalone browser.
  • @baekdal Thomas Baekdal on x
    Remember, this is ONLY possible because Apple decided that every app should have their own ‘in-app’ browser. If they had instead just sent links to the normal browser, apps wouldn't be able to inject JavaScript code into sites people visit https://twitter.com/...
  • @timsweeneyepic Tim Sweeney on x
    @ProgressChamber @actonline Apple and Google clearly still believe they can get away with all of their monopoly ties, rents and self-preferencing by gaslighting the industry with lies and selling the narrative that they're “only doing it to screw over Facebook”, which everyone se…
  • @vijayshekhar Vijay Shekhar Sharma on x
    ICYMI. Why shouldn't you use in app browser of Facebook or Instagram. https://twitter.com/...
  • @timsweeneyepic Tim Sweeney on x
    @BartWronsk To be very particular, I'm worried Apple will use this to further cripple the ability of apps to accept payments through a web browser in territories where it's a legislated right. They'll block these apps from opening logged-in browser sessions, adding hopeless payme…
  • @benadida Ben Adida on x
    1/ So there's news that Facebook and Instagram apps use the in-app browser and inject their own JavaScript into web pages users visit as they navigate the web after clicking a link in FB or Instagram. This is bad, and it's not just on FB and IG. https://krausefx.com/...
  • @slightlylate Alex Russell on x
    How can those apps show they're not shady? Any of: - Competet for default browser setting - if you can render webpages, you're halfway there! - Call CCT/SFSVC to layer the user's real browser into the app on link clicks - Let developers opt-out
  • @nicklockwood Nick Lockwood on x
    Uh, I mean *of course* they do this. This is the company that got the whole Internet to put trojan “like” buttons on their pages and then used them to track all visitors more than a decade ago. Working out what people are doing online is where most of FB's revenue comes from. htt…
  • @timsweeneyepic Tim Sweeney on x
    It's becoming nearly impossible to distinguish good faith but misguided efforts at mobile industry analysis from the naked mistruths that Apple and Google lobbying groups like @ProgressChamber and @ActOnline promulgate such as this here: https://twitter.com/...
  • @mnot Mark Nottingham on x
    “In-app browser.” Who ever thought that'd be an opportunity for abuse? https://twitter.com/...
  • @mrwcjoughin @mrwcjoughin on x
    @migueldeicaza I thought all browsers on iOS used webkit so therefore apple can still implement restrictions?
  • @timsweeneyepic Tim Sweeney on x
    Another strange argument that Apple is above all other companies. Apple is capable of tracking anything you do on any web site with any iOS web browser, because Apple imposes a browser engine monopoly. Why criticize particular apps when the statement is true of Apple itself? http…
  • @slightlylate Alex Russell on x
    Google has known for years that WebView IABs are bad for users, bad for privacy, and bad for the web. Apple knew about these loopholes when they launched about ATT. The thing is, they don't care as long as they rinse users through App Stores. https://infrequently.org/... https://…
  • @fraying Derek Powazek on x
    The Facebook and Instagram apps aren't listening to you through your phone's mic, but they are injecting code into any external link you visit to track everything you do. Stop using these apps! They're unsafe. https://twitter.com/...
  • @migueldeicaza Miguel de Icaza on x
    I would add, new AppStore rule that prohibits this behavior and an insta-ban of their apps until Facebook stops stealing private information from people. https://twitter.com/...
  • @francoisz @francoisz on x
    Native apps using webviews to let users browse external websites are just like rogue websites using frames to “steal” content in the 90s. Misappropriation, poor user experience, additional bugs, and #Security concerns, this must stop! https://www.holovaty.com/... https://twitter.…
  • @richfelker Rich Felker on x
    I actually can't believe they screwed this up and injected the malware as js into the loaded site where it could be observed introspectively, rather than just doing the spying from the native code in the browser that site js can't see. I'd assumed they'd done the latter. https://…