Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Researchers documented Meta Pixel and Yandex Metrica using Android localhost and related browser channels to connect website identifiers with identities held by native apps. The technique could get around some privacy protections, but it did not defeat every ad blocker or expose every visitor: it depended on a relevant tracking script and a matching app or service on the device. Researchers reported that the observed campaigns stopped after disclosure in 2025; that does not prove every possible browser-to-app tracking route is now closed.
What “localhost” means—and why it mattered
localhost and 127.0.0.1 ordinarily refer to the device itself. Developers use this loopback connection for legitimate purposes such as local testing and software integrations. The security concern was not localhost itself, but a webpage tracker using a local channel to communicate with a native Android app on the same phone—crossing a boundary users generally expect to separate browser activity from app identity.
In ordinary browsing, a first-party cookie is scoped to the site that set it. A local bridge could pass a site-specific identifier into an app that had access to a more persistent device or account identity. That created a way to correlate otherwise separate browsing identifiers without relying solely on conventional third-party cookies.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11How the web-to-app bridge worked
- A user had a relevant Meta or Yandex Android app installed and running a service that listened for local communications.
- The user visited a website whose page included Meta Pixel or Yandex Metrica.
- The tracker’s JavaScript attempted to communicate with the app through a local or related browser channel.
- The app and page exchanged identifiers or other data. The app could associate browser-side information with native app or device identifiers.
- The tracker sent the resulting information to the company’s servers.
The researchers documented HTTP(S), WebSocket and WebRTC-related variants. Meta’s observed methods included WebSocket and WebRTC techniques, including STUN/TURN and SDP manipulation. Yandex Metrica used HTTP(S) requests to fixed local ports and a domain resolving to loopback. These were not simply ordinary cookie reads: the bridge supplied a route between browser-side and app-side identity data. The USENIX Security 2026 paper and its full technical report describe the mechanisms.
#1 Best Overall
- YOUR CONTENT, SUPER SMOOTH: The ultra-clear 6.7" FHD+ Super AMOLED display of Galaxy A17 5G helps bring your content to life, whether you're scrolling through recipes or video chatting with loved ones.¹
- LIVE FAST. CHARGE FASTER: Focus more on the moment and less on your battery percentage with Galaxy A17 5G. Super Fast Charging powers up your battery so you can get back to life sooner.²
- MEMORIES MADE PICTURE PERFECT: Capture every angle in stunning clarity, from wide family photos to close-ups of friends, with the triple-lens camera on Galaxy A17 5G.
- NEED MORE STORAGE? WE HAVE YOU COVERED: With an improved 2TB of expandable storage, Galaxy A17 5G makes it easy to keep cherished photos, videos and important files readily accessible whenever you need them.³
- BUILT TO LAST: With an improved IP54 rating, Galaxy A17 5G is even more durable than before.⁴ It’s built to resist splashes and dust and comes with a stronger yet slimmer Gorilla Glass Victus front and Glass Fiber Reinforced Polymer back.
Meta’s documented data path
The research describes Meta Pixel passing the _fbp browser cookie and related browser information through browser-to-app channels. Facebook or Instagram could associate that information with identifiers available to the native app, then send combined data to Meta systems. A first-party cookie is not inherently a universal identifier; the concern was that the app bridge could make separate site-specific identifiers easier to correlate.
Yandex’s documented data path
In the reported Yandex flow, Metrica obtained obfuscated parameters from Yandex servers, sent them to a local listener, received encoded device-related identifiers, and returned identifiers and associated data to Yandex. The research identified HTTP ports 29009 and 30102, HTTPS ports 29010 and 30103, and yandexmetrica.com resolving to 127.0.0.1 for this purpose. These are historical findings, not a current port list or a recommendation to scan or block those ports.
What could be linked—and what the findings do not show
The documented identifiers included Meta’s _fbp cookie and browser metadata, Yandex-side identifiers and Android Advertising ID-related data, and persistent app or device identifiers. The bridge could associate website-origin or browsing-activity information with an app identity, and could make multiple site-specific first-party cookies linkable through that identity.
Recommended Free Tools
Rank #2
- Carrier: This phone is locked to Tracfone, which means this device can only be used on the Tracfone wireless network. Tracfone plan required, activating is easy, just 3 steps.
- DISPLAY: Immersive viewing on a 6.7-inch super-bright 120Hz display with powerful stereo speakers and Bass Boost for cinematic entertainment.
- CAMERA SYSTEM: Advanced 50MP Quad Pixel camera captures sharp, detailed photos and videos in any lighting condition
- PERFORMANCE: Lightning-fast 5G connectivity paired with a powerful processor and RAM Boost for smooth multitasking.
- BATTERY LIFE: Long-lasting 5000mAh battery with TurboPower charging technology delivers hours of power in minutes.
This is a tracking and identity-correlation finding, not evidence that the technique stole passwords, login cookies, private messages or arbitrary files. Nor does it establish that every page visited by every user was uploaded. A relevant tracker had to be present and able to communicate with a corresponding app or service for the described handoff to occur.
Which Android apps and sites were involved
The researchers reported testing Facebook, Instagram, Yandex Maps, Yandex Navigator, Yandex Browser, Yandex Search, Yandex Go and Yandex Metro. The app versions in the project are research test conditions; they do not establish that every release behaved identically or describe current versions. The findings concern Android. They should not be generalized to iPhones or desktop browsers without separate evidence.
For scale, the researchers cite BuiltWith estimates of more than 5.8 million sites carrying Meta Pixel and nearly 3 million carrying Yandex Metrica, while noting that other datasets produce lower counts. In crawls of the top 100,000 homepages, they observed localhost activity on 15,819 EU sites and 17,368 US sites. Among pages with Yandex Metrica, localhost activity occurred without consent in about 83.5% of US observations and 84.4% of EU observations. These are crawl measurements, not counts of affected people or proof that every observed request successfully linked an identity. Details and qualifications appear on the research project site.
Rank #3
- YOUR CONTENT, SUPER SMOOTH: The ultra-clear 6.7" FHD+ Super AMOLED display of Galaxy A17 5G helps bring your content to life, whether you're scrolling through recipes or video chatting with loved ones.¹
- LIVE FAST. CHARGE FASTER: Focus more on the moment and less on your battery percentage with Galaxy A17 5G. Super Fast Charging powers up your battery so you can get back to life sooner.²
- MEMORIES MADE PICTURE PERFECT: Capture every angle in stunning clarity, from wide family photos to close-ups of friends, with the triple-lens camera on Galaxy A17 5G.
- NEED MORE STORAGE? WE HAVE YOU COVERED: With an improved 2TB of expandable storage, Galaxy A17 5G makes it easy to keep cherished photos, videos and important files readily accessible whenever you need them.³
- BUILT TO LAST: With an improved IP54 rating, Galaxy A17 5G is even more durable than before.⁴ It’s built to resist splashes and dust and comes with a stronger yet slimmer Gorilla Glass Victus front and Glass Fiber Reinforced Polymer back.
Why private browsing, cookie deletion and VPNs were not complete defenses
Private browsing and cookie clearing primarily affect browser-held state. They do not necessarily erase an app’s account identity, device identifier or stored state. If a page can reach an app that supplies a durable identifier, a browser reset alone may not prevent the two sides from being associated.
A VPN changes how network traffic is routed and can conceal a public IP address from some observers; it does not inherently stop a webpage from communicating with an app on the same device. The researchers also reported that resetting the mobile advertising ID or separating Android work and personal profiles did not necessarily prevent the documented forms of linkage. These measures can still serve other privacy purposes, but they are not substitutes for blocking the tracker or the local communication channel.
Consent timing and a separate interception risk
In their crawls, researchers found Meta Pixel and Yandex Metrica initiating localhost bridging before users accepted cookie-consent banners. A script attempting a connection before consent is not identical to a successful identity exchange, and neither finding by itself determines whether a particular site broke a particular law. The study raises a serious question about user expectations and consent, but legal conclusions depend on the site, jurisdiction and facts; the research is not a regulator’s case-specific ruling.
Yandex’s reported HTTP design also raised a distinct security issue: another Android app listening on the same ports could potentially observe requests and infer visited sites from request metadata, such as the Origin header. Researchers demonstrated the possibility with a proof-of-concept app, but said they had not observed an unrelated app already listening on those ports. This interception risk is different from the intended app receiving data for Meta or Yandex. Do not install an untrusted proof-of-concept app to test it.
Rank #4
- PRIVACY DISPLAY: Automatically hide your screen from those beside you. The built-in privacy display can be preset¹ to turn on when receiving notifications, typing passwords, or using specific apps
- TYPE IT IN. TRANSFORM IT FAST: Enhance any shot in seconds on your smartphone by using Photo Assist² with Galaxy AI.³ Add objects, restore details, or apply new styles by simply typing or tapping
- NIGHTS, CAPTURED CLEARLY: From gigs to city lights, record and capture moments after dark with clarity using Nightography so your photos and videos stay crisp and clear on your Samsung Galaxy
- MAKE IT. EDIT IT. SHARE IT: Turn everyday moments into something personal with creative tools built right into your mobile phone, whether it’s a special contact photo, custom wallpaper, an invitation or more⁴
- HELP THAT KEEPS UP: Stay in the moment while Now Nudge with Galaxy AI helps you respond faster and stay organized with smart suggestions⁵ that appear exactly when you need them on your phone
What happened after disclosure
The researchers identify the earliest known Yandex Metrica localhost-linking behavior in May 2017 and the start of Meta’s observed campaign in September 2024. They say they discovered the bridge in January 2025 and privately notified Android, browser vendors and relevant authorities between March and May. Initial browser mitigations began rolling out in late May.
On June 3, 2025, the researchers reported that Meta Pixel had stopped sending localhost requests and that Yandex had also stopped the described practice. Meta told The Register it was discussing a “potential miscommunication” with Google regarding policy; that is not an admission to every allegation. The report does not establish a comparable public Yandex response. The Register’s June 2025 account covered Meta’s pause and response.
The observed campaigns should therefore be described as historical, not as verified ongoing Meta and Yandex operations. The remaining concern is architectural: a browser’s protections for one local protocol may not cover every way a page can reach local services.
Best Value
- Carrier: This phone is locked to Tracfone, which means this device can only be used on the Tracfone wireless network. Activating is easy, just 3 steps.
- ACTIVATION Promotion: Includes 1500 min, 1500 texts & 1500 MB Data + add more as you need it
- CAMERA SYSTEM: 50MP Quad Pixel camera. Capture sharper, more vibrant photos day or night with 4x the light sensitivity.
- PERFORMANCE: Blazing-fast Qualcomm performance. Get the speed you need for great entertainment with a Snapdragon 680 processor and 4GB of RAM.
- 64GB built-in storage. Get plenty of room for photos, movies, songs, and apps. Made for US
What browser protections changed—and their limits
Browser behavior varies by release, channel, platform and settings. The following are historical findings from the researchers’ testing, not guarantees for every current installation.
| Browser or protection | Historical research finding |
|---|---|
| Brave | Blocklists and localhost protections stopped the tested forms; the paper notes limitations involving domains resolving to loopback and WebRTC. |
| DuckDuckGo | Its blocklist stopped most relevant domains in testing; researchers reported an update after disclosure. Domain blocking does not inherently cover every local channel. |
| Firefox | Enhanced Tracking Protection in Strict mode blocked Meta Pixel in the researchers’ measurements. Settings and versions matter. |
| Chrome | Temporary port restrictions and later Local Network Access protections were deployed. |
| Vivaldi | The default privacy setting was reported as insufficient in original testing, while stronger tracker blocking appeared to prevent leakage. |
The USENIX paper reports that Chrome Stable introduced Local Network Access (LNA) in version 142 on October 28, 2025, with separate permissions for local-network and loopback-network access. In the paper’s January 2026 snapshot, LNA had shipped in Chrome Stable 142 and Firefox Nightly 143, while WebKit had expressed intent to ship. Those are dated implementation details, not a statement of current availability in every browser build.
LNA is an important barrier, not a universal fix. The paper reports incomplete or experimental support for WebSockets, WebRTC and WebTransport in the cited implementation. It also demonstrates other technically exploitable paths involving global-unicast IPv6 addresses exposed through WebRTC, mDNS queries and .local hostnames, and UUID-like local names generated by WebRTC. Researchers said their crawls did not show active abuse through these additional paths. They are residual technical risks, not evidence that Meta or Yandex deployed them.
Practical steps Android users can take
- Keep Android and your browser updated. Browser security protections change over time; update through your device’s normal software and app update channels.
- Use a browser with tracker blocking and local-network protections. Enable its stronger tracking-protection options if you can tolerate occasional site breakage. Check the browser’s current permissions and settings rather than assuming a feature from an older test is present.
- Block tracker scripts where practical. Browser filtering or a network-level filter can prevent a script from running, which prevents that script’s bridge attempt. Incomplete blocklists may miss alternate domains or protocols.
- Consider whether you need the corresponding native apps. Uninstalling Facebook, Instagram or relevant Yandex apps can remove that app’s local listener, but does not stop ordinary web tracking or address unrelated apps.
- Review local-network prompts carefully. Grant access only when the site’s function makes sense to you; a prompt should not be treated as proof that the requested access is harmless.
- Do not rely on one reset alone. Incognito mode, cookie deletion, advertising-ID resets and VPN use can help with other risks but are not complete defenses against same-device app communication.
More aggressive blocking can disrupt legitimate local integrations, including authentication helpers, development tools, casting, password managers or enterprise software. Blocking known ports or all localhost traffic can also break useful functions, which is why the historical Yandex port numbers should not be treated as a universal blocking recipe.
The unresolved design problem
Local networking has legitimate uses, while browsers and operating systems must prevent websites from quietly turning those local services into cross-context tracking channels. The durable response requires defenses at several layers: browsers need consistent controls across HTTP and other protocols; app platforms need to constrain unexpected local listeners; and tracker filters need to block scripts before they initiate a handoff. A permission prompt or blocklist can reduce exposure, but the later protocol demonstrations show why one mitigation cannot be assumed to cover every route.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

