4 ms·
It does sound fantastical. A piece of code that can violate the same origin policy would be a huge vulnerability. Meta could be working with other sites to shar
by bink 1y ago
It does sound fantastical. A piece of code that can violate the same origin policy would be a huge vulnerability. Meta could be working with other sites to share data on users via code running on both sites, but snooping on tax data without the IRS helping? Unlikely.
I can only assume they're suggesting that companies like Intuit and H&R Block are sharing this data with Meta, but that seems like a huge violation of privacy and with tax data it might even be illegal.
- macNchz 1y agoIt's effectively malware—this article has some more detail: https://arstechnica.com/security/2025/06/meta-and-yandex-are-de-anonymizing-android-users-web-browsing-identifiers/ https://arstechnica.com/security/2025/06/meta-and-yandex-are... Basically, they created a channel between the browser and a localhost webserver running in their native apps, by abusing the ability to set arbitrary metadata on WebRTC connections. That way, they were able to exfiltrate tracking cookies out of the browser's sandbox to the native app, where they could be associated with your logged-in user identity.
- zzleeper 1y agoIs there any way to fix it within Android? damn...
- petre 1y agoYes, don't install their native apps.
- dogtierstatus 1y agothat's great but cheaper android phones come with built-in Meta apps/services which cant even be uninstalled.
- petre 1y agoYou can still disable them and I think also uninstall with adb.
- tholdem 1y agoYou are implying Meta and others were able to just siphon data from any website via WebRTC using their native apps, but this was not the case. They were only able to track which websites you visited if that website already embedded the company tracking. Many websites do, but not all.