Covert Web-to-App Tracking via Localhost on Android localmess.github.io

We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users. We found that native Android apps—including Facebook, Instagram, and several Yandex apps including Maps and Browser—silently listen on fixed local ports for tracking purposes.

This is why I hate native apps, they can do what they want.

Published: June 5, 2025
Tags: #privacy