<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/how-meta-and-yandex-are-circumventing-android-s-privacy-protections-bf5crfu6o" -->

---
title: How Meta and Yandex are Circumventing Android&#x27;s Privacy...
description: Security researchers discovered that Meta and Yandex were using Android apps to exploit localhost ports for covert user tracking, bypassing privacy protections...
canonical: https://daily.dev/posts/how-meta-and-yandex-are-circumventing-android-s-privacy-protections-bf5crfu6o
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: How Meta and Yandex are Circumventing Android&#x27;s Privacy Protections | daily.dev
og:description: Security researchers discovered that Meta and Yandex were using Android apps to exploit localhost ports for covert user tracking, bypassing privacy protections...
og:url: https://daily.dev/posts/how-meta-and-yandex-are-circumventing-android-s-privacy-protections-bf5crfu6o
og:image: https://api.daily.dev/og/posts/BF5CrFu6o.png
og:image:alt: How Meta and Yandex are Circumventing Android&#x27;s Privacy Protections
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How Meta and Yandex are Circumventing Android's Privacy Protections

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Security researchers discovered that Meta and Yandex were using Android apps to exploit localhost ports for covert user tracking, bypassing privacy protections like incognito mode and cookie clearing. The 'Local Mess' technique linked web browsing data to mobile app identities, breaking Android's sandboxing protections. Meta's tracking affected Facebook and Instagram users across all major browsers, while Yandex employed similar methods since 2017. Following disclosure and Google's policy violation confirmation, Meta removed the tracking code and browser vendors implemented countermeasures, with Chrome 137 blocking the SDP munging technique.

## Content

Security researchers have uncovered that Meta and Yandex were employing Android apps to exploit localhost ports and track users by linking web browsing data to user identities. This practice allowed them to bypass privacy protections such as cookie clearing and incognito mode. The tracking code was embedded in millions of websites, converting temporary web identifiers into persistent mobile app identities. This effectively breached Android's sandboxing protections that normally isolate web browsers from native mobile apps. The method, known as 'Local Mess', shares identifiers between browsers and apps, linking web activity to app accounts.

Meta’s Pixel script transmitted tracking data from websites to Facebook and Instagram apps, connecting web cookies to user accounts without consent. This was possible across all major browsers, even in incognito mode. Yandex similarly utilized this technique since 2017, while Meta began in late 2024. Following the discovery, and Google’s confirmation of policy violations, Meta halted the feature and removed the tracking code. Yandex has denied collecting sensitive data.

Browser vendors, in response to the findings, have started implementing countermeasures. Chrome 137, for example, has blocked the SDP munging technique, and other browsers are developing similar fixes to prevent such exploitations. This disclosure has prompted significant changes to safeguard user privacy on Android devices, affecting billions of users across millions of websites.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#android](https://daily.dev/tags/android), [#privacy](https://daily.dev/tags/privacy)

[View this post on daily.dev](https://daily.dev/posts/how-meta-and-yandex-are-circumventing-android-s-privacy-protections-bf5crfu6o)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"How Meta and Yandex are Circumventing Android's Privacy Protections","url":"https://daily.dev/posts/how-meta-and-yandex-are-circumventing-android-s-privacy-protections-bf5crfu6o","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/how-meta-and-yandex-are-circumventing-android-s-privacy-protections-bf5crfu6o"},"datePublished":"2025-06-03T14:52:50.576Z","dateModified":"2025-06-04T17:45:08.083Z","description":"Security researchers discovered that Meta and Yandex were using Android apps to exploit localhost ports for covert user tracking, bypassing privacy protections...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d5be88395952c1d96e3a3a45e1de35c8?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d5be88395952c1d96e3a3a45e1de35c8?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/how-meta-and-yandex-are-circumventing-android-s-privacy-protections-bf5crfu6o","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,android,privacy","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"How Meta and Yandex are Circumventing Android's Privacy Protections"}]}
```

