A detailed look at how Facebook and Instagram for iOS open links with a custom in-app browser, letting Meta track every interaction including entering passwords
How the seemingly innocuous “in-app web browsers” on iOS/Android are a really bad thing, and a proposal for how to fix that. With a little web history thrown in. https://www.holovaty.com/... @katebevan : You can turn this off on both Facebook and Twitter. On Facebook, tap the hamburger menu, then tap Settings, then Media (yeah, it's sneakily hidden). Down at the bottom of the next page, tick Links open externally. https://twitter.com/... @katebevan : Don't know why everyone is sounding so surprised at this. Of *course* Facebook tracks you via its in-app browser. So does Twitter, for that matter. https://twitter.com/... Alex Russell / @slightlylate : If you want an inkling of the reason I'm so upset about “in app browsers”, here's someone else noticing what I've been wittering on about: https://krausefx.com/... Aaron Parecki / @aaronpk : In case you needed a reminder about why we care so much about OAuth/OIDC flows being used in the system browser and not embedded browsers, Instagram injects their own tracking code in every web page you visit inside Instagram https://krausefx.com/... Armin Ronacher / @mitsuhiko : The the surprise if absolutely nobody Meta does shady stuff in their in app browser. I really want to know how devs within Meta justify this type of stuff. https://krausefx.com/... Felix Krause / @krausefx : @katebevan At least on iOS, you can't turn this off for Instagram. Also, Twitter for iOS does NOT track your, they use the recommended SFSafariViewController, which runs in a separate process @katebevan : Just to be clear, my screenshots are Android. Not sure what the situation is on iOS; I don't have any Apple devices, tho Felix suggests it's not so egregious on iOS https://twitter.com/...
Context & Ripple Effects
Apple’s iOS 14 privacy changes had already pushed Facebook and Instagram to ask users to permit tracking in prompts framed around keeping their services free; the apps’ tracking-permission messaging after iOS 14 provides the backdrop for scrutiny of data collection inside links opened from their feeds.
The distinction is not uniform across Meta’s apps: Facebook exposes an external-link setting, while Instagram does not. Later coverage of Meta building a Chromium-based browser engine for Facebook on Android indicates that control of the link-opening layer is becoming a product choice across platforms.
First-order effects
- Meta can observe interactions within Facebook and Instagram’s embedded iOS browsing flow; Instagram’s reported page-level tracking-code injection makes that exposure extend to activity on sites users visit from the app.
- Facebook users can route links to an external browser through a setting, while Instagram users on iOS lack an equivalent opt-out.
Second-order effects
- Publishers and login providers whose pages open inside Instagram must treat Meta’s embedded browser as an additional intermediary around reader and account interactions.
- Meta’s planned Android browser engine gives Facebook a route to retain control over link handling beyond iOS, while Twitter’s use of a separate-process Safari view marks a different implementation choice.
Third-order effects
- If app-owned browsers continue to replace handoffs to the system browser, privacy choice will increasingly depend on each app’s disclosure and exit controls rather than on the browser protections users selected.
- The resulting divide between Facebook’s external-link option and Instagram’s lack of one points toward platform-level governance of embedded webviews becoming a durable consumer-protection issue.
The trend: Social platforms are treating the browser opened from their apps as a controlled data and product surface, rather than a neutral handoff to the user’s chosen browser.
Related: SDK governance gap · Facebook · Instagram · Meta’s Android browser engine plan · Meta’s iOS tracking-permission prompts
Related Coverage
- Meta injecting code into websites to track its users, research says The Guardian · Alex Hern
- Facebook and Instagram apps can track users via their in-app browsers Engadget · Steve Dent
- Is App Tracking Transparency Actually Doing Anything Truly Significant? Daring Fireball · John Gruber
- Meta Injecting Code Into Websites Visited By Its Users To Track Them, Research Says Slashdot · BeauHD
- Facebook & Instagram Track Users Even In The In-App Browsers Android Headlines · Arthur Brown
- In-app browsers like those in Facebook and Instagram are a big privacy risk, developer shows 9to5Mac · Ben Lovejoy
- Instagram, Facebook apps track users' data without explicit consent, analysis finds WRAL TechWire
- Facebook's in-app browser can track you on other websites, research says Silicon Republic · Leigh Mc Gowran
- Let websites framebust out of native apps Adrian Holovaty
- Instagram and Facebook's In-App Browser Bypasses Apple Tracking Protections: Report iPhone in Canada Blog · Nehal Malik
- In-App Browsers Used by Companies Like Instagram and Facebook Are Massive Privacy Risk Warns Developer The Mac Observer · Nick deCourville
- Instagram Can Track User's Web Activity Including Confidential Information, Via In-App Browser: Report International Business Times · Ians
- Privacy tracking within in-app browsers Insanely Great Mac · Mike Flaminio
Discussion
-
@krausefx
Felix Krause
on x
💥 New Post: Instagram & Facebook tracks everything you do on any website in their in-app browser https://krausefx.com/... https://twitter.com/...
-
@simonw
Simon Willison
on x
This is really grim, if not entirely unexpected: apparently the Instagram mobile app injects additional JavaScript into every page that's loaded using the in-app embedded browser - here's the tool @KrauseFx built to track changes made to the DOM when loading a page https://twitte…
-
@katebevan
Kate Bevan
on x
On Twitter, tap your avatar, then Settings and privacy, then Accessibility, display and languages, then Display, then on the next page, toggle off Use in-app browser. You're welcome https://twitter.com/...
-
@elkmovie
Michael Love
on x
If it weren't for antitrust regulators breathing down their necks I'd be worried that Apple was going to ban the use of WKWebView for browsing and limit in-app browsers to Safari, which would kill my Web Reader feature. (They may mandate some kind of warning alert though) https:/…
-
@aulia
Aulia Masna
on x
Crafty yet sleazy behavior from Meta, here. Should push links to Safari all the time to avoid this. https://twitter.com/...
-
@anildash
Anil
on x
If you click a link in your Instagram or Facebook app, Meta (Facebook) actually modifies the pages you're reading so that it can track every single thing you do on those sites. https://twitter.com/...
-
@drbarnard
David Barnard
on x
“The more I think about it, the more I cannot believe webviews with unfettered JavaScript access to third-party websites ever became a legitimate, accepted technology. It's bad for users, and it's bad for websites.” https://twitter.com/...
-
@froomkin
@froomkin
on x
I have long wondered why, when I click a Twitter link on my iPhone, it opens inside Twitter instead of in a normal browser. Now I know. The answer is evil: https://www.holovaty.com/...
-
@andreban
André Bandarra
on x
This is more complicated than it looks - all browsers on iOS but Safari are based on WebView. On Android, at least Opera Mini and DuckDuckGo are built on top of WebView. Implementing X-Frame-Options on the WebView level would make those browsers unviable. https://twitter.com/...
-
@jbrodsky
Jay Brodsky
on x
Asking the big question “why do we let the in-app webview do that?” ("That" being break our sites, inject JavaScript, steal IP, etc.) @adrianholovaty ties the past to the present. A must-read. https://twitter.com/...
-
@sil
Stuart Langridge
on x
This is a smart idea: Apple and Google should make in-app browsers respect X-Frame-Options: Deny to open a page in the user's chosen web browser. As noted, they have zero commercial incentive to do so... but lots of user experience incentive. What happens when the two conflict? h…
-
@choldgraf
Chris Holdgraf
on x
Reminder #1000 that if you're not paying for it, and the organization doesn't have a clear alternative story about how its free thing makes it money, then you're the product https://twitter.com/...
-
@adrianholovaty
Adrian Holovaty
on x
This is appalling behavior by Instagram and Facebook. It's time to do something about it. https://twitter.com/...
-
@hhariri
Hadi Hariri
on x
If there's anything Facebook has taught me, it's that no matter what you do, you'll get away with it. Time and time again. https://krausefx.com/...
-
@zachleat
Zach Leatherman
on x
Apple's security argument as to why it can't allow third party browser engines on iOS 🤝 Apple allowing Instagram and Facebook in-app browsers on iOS to inject tracking scripts on any web site https://krausefx.com/...
-
@krausefx
Felix Krause
on x
Why is this a big deal? Instagram & Facebook actively work around the new App Tracking Transparency System which was designed to prevent exactly this kind of abuse, to keep tracking users outside their ecosystem https://twitter.com/...
-
@krausefx
Felix Krause
on x
Apple has built “App-Bound Domains”, which could help avoid this kind of platform abuse, however it's not mandatory yet. Unfortunately, even the iOS Lockdown Mode doesn't prevent Instagram fetching user data from third party websites. https://twitter.com/...
-
@slightlylate
Alex Russell
on x
Adrian's proposed solution mirrors mine: headers should allow pages to “punch-out” of sub-standard treatment while we breathlessly await mobile OSes enforcing reasonable, pro-privacy, pro-user, pro-web policies. On second thought, don't hold your breath.
-
@funnymonkey
Bill Fitzgerald
on x
This is a really interesting writeup from @KrauseFx on how the Instagram app subjects users to pervasive tracking and circumvents the privacy protections recently rolled out in iOS. https://krausefx.com/... A few notes/observations 1/x
-
@adrianholovaty
Adrian Holovaty
on x
My first blog post in four years (!) — How the seemingly innocuous “in-app web browsers” on iOS/Android are a really bad thing, and a proposal for how to fix that. With a little web history thrown in. https://www.holovaty.com/...
-
@krausefx
Felix Krause
on x
@katebevan At least on iOS, you can't turn this off for Instagram. Also, Twitter for iOS does NOT track your, they use the recommended SFSafariViewController, which runs in a separate process
-
@slightlylate
Alex Russell
on x
If you want an inkling of the reason I'm so upset about “in app browsers”, here's someone else noticing what I've been wittering on about: https://krausefx.com/...
-
@katebevan
@katebevan
on x
You can turn this off on both Facebook and Twitter. On Facebook, tap the hamburger menu, then tap Settings, then Media (yeah, it's sneakily hidden). Down at the bottom of the next page, tick Links open externally. https://twitter.com/...
-
@katebevan
@katebevan
on x
Don't know why everyone is sounding so surprised at this. Of *course* Facebook tracks you via its in-app browser. So does Twitter, for that matter. https://twitter.com/...
-
@aaronpk
Aaron Parecki
on x
In case you needed a reminder about why we care so much about OAuth/OIDC flows being used in the system browser and not embedded browsers, Instagram injects their own tracking code in every web page you visit inside Instagram https://krausefx.com/...
-
@mitsuhiko
Armin Ronacher
on x
The the surprise if absolutely nobody Meta does shady stuff in their in app browser. I really want to know how devs within Meta justify this type of stuff. https://krausefx.com/...
-
@katebevan
@katebevan
on x
Just to be clear, my screenshots are Android. Not sure what the situation is on iOS; I don't have any Apple devices, tho Felix suggests it's not so egregious on iOS https://twitter.com/...
-
@krausefx
Felix Krause
on x
Meta has provided additional information, which I included in the publication. The article is still correct, however it's not the Meta Pixel that gets injected, but a script called “pcm.js” https://krausefx.com/... https://twitter.com/... https://twitter.com/...
-
@openwebadvocacy
@openwebadvocacy
on x
In-App Browsers should not be allowed to subvert a user's choice of browser. Both Apple and Google should enforce this from an OS level. OWA is advocating for users to be given control over what happens when they tap a link no matter what the app is. https://www.theguardian.com/ …
-
@slightlylate
Alex Russell
on x
Folks, this in-app browser thing really isn't complicated: An app that isn't a browser, but steals traffic from browsers for web content it doesn't serve, is shady af.
-
@counternotions
Kontra
on x
This is completely blown out of proportion: How else could Facebook stand up to Apple for small businesses everywhere?! ↓ https://twitter.com/...
-
@benadida
Ben Adida
on x
4/ I sincerely hope both Apple and Google bring the hammer down on FB/IG unless they disclose to users exactly what they're doing. This is serious.
-
@migueldeicaza
Miguel de Icaza
on x
@mrwcjoughin The engine is WebKit, but there are three way of using it: WKWebView (what Facebook is using to inject spyware), SFSafariViewController (they can't inject it, had plenty of real features of the full safari and JIT) and launching the standalone browser.
-
@baekdal
Thomas Baekdal
on x
Remember, this is ONLY possible because Apple decided that every app should have their own ‘in-app’ browser. If they had instead just sent links to the normal browser, apps wouldn't be able to inject JavaScript code into sites people visit https://twitter.com/...
-
@timsweeneyepic
Tim Sweeney
on x
@ProgressChamber @actonline Apple and Google clearly still believe they can get away with all of their monopoly ties, rents and self-preferencing by gaslighting the industry with lies and selling the narrative that they're “only doing it to screw over Facebook”, which everyone se…
-
@vijayshekhar
Vijay Shekhar Sharma
on x
ICYMI. Why shouldn't you use in app browser of Facebook or Instagram. https://twitter.com/...
-
@timsweeneyepic
Tim Sweeney
on x
@BartWronsk To be very particular, I'm worried Apple will use this to further cripple the ability of apps to accept payments through a web browser in territories where it's a legislated right. They'll block these apps from opening logged-in browser sessions, adding hopeless payme…
-
@benadida
Ben Adida
on x
1/ So there's news that Facebook and Instagram apps use the in-app browser and inject their own JavaScript into web pages users visit as they navigate the web after clicking a link in FB or Instagram. This is bad, and it's not just on FB and IG. https://krausefx.com/...
-
@slightlylate
Alex Russell
on x
How can those apps show they're not shady? Any of: - Competet for default browser setting - if you can render webpages, you're halfway there! - Call CCT/SFSVC to layer the user's real browser into the app on link clicks - Let developers opt-out
-
@nicklockwood
Nick Lockwood
on x
Uh, I mean *of course* they do this. This is the company that got the whole Internet to put trojan “like” buttons on their pages and then used them to track all visitors more than a decade ago. Working out what people are doing online is where most of FB's revenue comes from. htt…
-
@timsweeneyepic
Tim Sweeney
on x
It's becoming nearly impossible to distinguish good faith but misguided efforts at mobile industry analysis from the naked mistruths that Apple and Google lobbying groups like @ProgressChamber and @ActOnline promulgate such as this here: https://twitter.com/...
-
@mnot
Mark Nottingham
on x
“In-app browser.” Who ever thought that'd be an opportunity for abuse? https://twitter.com/...
-
@mrwcjoughin
@mrwcjoughin
on x
@migueldeicaza I thought all browsers on iOS used webkit so therefore apple can still implement restrictions?
-
@timsweeneyepic
Tim Sweeney
on x
Another strange argument that Apple is above all other companies. Apple is capable of tracking anything you do on any web site with any iOS web browser, because Apple imposes a browser engine monopoly. Why criticize particular apps when the statement is true of Apple itself? http…
-
@slightlylate
Alex Russell
on x
Google has known for years that WebView IABs are bad for users, bad for privacy, and bad for the web. Apple knew about these loopholes when they launched about ATT. The thing is, they don't care as long as they rinse users through App Stores. https://infrequently.org/... https://…
-
@fraying
Derek Powazek
on x
The Facebook and Instagram apps aren't listening to you through your phone's mic, but they are injecting code into any external link you visit to track everything you do. Stop using these apps! They're unsafe. https://twitter.com/...
-
@migueldeicaza
Miguel de Icaza
on x
I would add, new AppStore rule that prohibits this behavior and an insta-ban of their apps until Facebook stops stealing private information from people. https://twitter.com/...
-
@francoisz
@francoisz
on x
Native apps using webviews to let users browse external websites are just like rogue websites using frames to “steal” content in the 90s. Misappropriation, poor user experience, additional bugs, and #Security concerns, this must stop! https://www.holovaty.com/... https://twitter.…
-
@richfelker
Rich Felker
on x
I actually can't believe they screwed this up and injected the malware as js into the loaded site where it could be observed introspectively, rather than just doing the spying from the native code in the browser that site js can't see. I'd assumed they'd done the latter. https://…