Meta says Facebook for Android will soon use its own Chromium-based in-app browser engine, citing security and stability as reasons for its WebView alternative
When you open a link while in another app, it usually launches in your browser (e.g., Chrome) or a Custom Tab.
9to5GoogleAbner Li
Context & Ripple Effects
The default way an Android app opens a link has been a contested layer since Google introduced Chrome's Custom Tabs in 2015 as a faster alternative to raw WebView — a mechanism that kept users inside Chrome's engine while letting apps style the shell around it. Meta is now stepping off both rails: Facebook for Android will ship its own Chromium-based in-app browser engine instead of relying on WebView or Custom Tabs, with security and stability cited as the rationale.
The timing matters because in-app browsers are already under a microscope: researcher Felix Krause showed in August that Facebook and Instagram's custom in-app browser on iOS could observe every interaction, including passwords typed into pages opened from the apps (that iOS in-app browser tracking analysis). Moving Android to a self-controlled engine puts more of the link-opening path under Meta's direct control rather than Google's.
First-order effects
Android users tapping links inside Facebook will render those pages in Meta's own Chromium-based engine rather than Chrome Custom Tabs or system WebView, shifting rendering behavior, cookie storage, and update cadence from Google's pipeline to Meta's.
Second-order effects
Google loses a slice of Chrome-driven engagement on Android every time a major app abandons Custom Tabs, and if Meta's move reads as successful, other large app developers face pressure to build or bundle their own engines — fragmenting what 'the Android browser' even means.
Given the Krause findings on iOS, Meta's stated security-and-stability framing will be tested against scrutiny of what its self-controlled Android engine can observe about user activity inside opened links.
Third-order effects
If large platforms keep pulling web rendering in-house, the browser stops being a neutral shared layer supplied by the OS vendor and becomes an asset each super-app controls — weakening the default-browser distribution model Google built on Android and inviting regulator attention to who can see what inside embedded webviews.
The trend: Super-apps are replacing OS-provided browser layers with their own engines, turning in-app link opening from infrastructure into a controlled, proprietary surface.
👀 Facebook's Android app no longer (exclusively) will rely on the system's WebView, but now ships with its own Chromium-based WebView: https://engineering.fb.com/.... Read all about this in @n8Schloss' blog post. Does this change now make Facebook a browser for good? 🤔
@zachleat @KrauseFx They don't need scripts to know what posts you click on or what ulrs the embedded views navigate to. Those are all standard APIs exposed by the webview. What the various companies do with the data they have access to is a policy issue, not a technical one.
@slightlylate :wave: lol, I was thinking of you when I read this too ;-) I wouldn't go so far as to say this isn't good for anyone but FB. The claims in the blog about quality improvements make sense, and I can see how the overall user experience would benefit. I get your point t…
Facebook gets a pretty big side-eye here forking Android's WebView for “security reasons.” Anyway, I'm reminded of @KrauseFx's research that showed Facebook shipped a bunch of tracking scripts from their in-app browsers on iOS: https://krausefx.com/... Unrelated I'm sure. https:/…
This is surely going to bloat out the FB Android app even more. And because it's Facebook, can't help but wonder what tracking end up embedding when they control the entire browser engine https://engineering.fb.com/...
@tomayac @n8Schloss A little bit, but more importantly it helps Facebook gather even more data than before. I would strongly advise hitting the “open in default browser” when in comes to in-app links.
@patmeenan @KrauseFx I would like to see those! I don't think you would make the claim that Facebook *isn't* tracking folks via these mechanisms though, would you?
Meta is working on its Chromium-based engine for the In-App Facebook Mobile Browser. It will replace the webview currently in use on Android for that browsing experience. As you know, Apple won't accept that engine in iOS and iPadOS. https://engineering.fb.com/...
@zachleat ... Yeah, having built a browser in the past based on webviews. Script injection was a requirement to solve basic expectations of browsing because webviews are not browsers by themselves. It's was surprising to see this surface as a new thing tbh. I'd guess fb is gettin…
@zachleat @KrauseFx You should see how many scripts Chrome ships for it's iOS webview-based browser ;-) Injected scripts doesn't necessarily mean “tracking”.
@tomayac @n8Schloss They know Apple will loosen up and will ship this to iOS too! Even more privacy invasion by @Meta! At least @slightlylate will be happy in that future! ;)