An ex-Google engineer has found that Meta is using code to follow users clicking links within its in-app browser.
The Facebook and Instagram apps render all third-party links and ads through a custom browser built into the programmes, rather than an external browser app such as Google Chrome or Firefox.
Sending users to this internal browser provides Meta with the ability to track every interaction with external websites.
The app injects their JavaScript code into every website shown through the in-app browser. Injecting custom scripts into third party websites allows them to monitor all user interactions, including, text selections, screenshots, addresses and credit card numbers, causing risks for users.
Felix Krause, a privacy researcher who founded an app development tool acquired by Google in 2017, carried out the research.
In a blog post, he commented: “The Instagram app injects their tracking code into every website shown, including when clicking on ads, enabling them [to] monitor all user interactions, like every button and link tapped, text selections, screenshots, as well as any form inputs, like passwords, addresses and credit card numbers.”
Krause added in his post that many companies use this form of internal browser, which allows an app developer to use the built-in Safari with all its features. They can do this without making the user leave your application.
A spokesperson for Meta said: “We intentionally developed this code to honour people’s [Ask to track] choices on our platforms.
“The code allows us to aggregate user data before using it for targeted advertising or measurement purposes. We do not add any pixels. Code is injected so that we can aggregate conversion events from pixels.”
They added: “For purchases made through the in-app browser, we seek user consent to save payment information for the purposes of autofill.”
Krause discovered the code injection by building a tool that could list all the extra commands added to a website by the browser. He discovered that the Meta tracking tool allows the company to follow a user around the web and build an accurate profile of their interests.
The company does not disclose to the user that it is rewriting webpages in this way. No such code is added to the in-app browser of WhatsApp, according to his research.
“Javascript injection” – the practice of adding extra code to a webpage before it is displayed to a user – is frequently classified as a type of malicious attack.
Krause’s research found that there is no suggestion that Meta has used its Javascript injection to collect such sensitive data. In the company’s description of the Meta Pixel it simply said the tool “allows you to track visitor activity on your website”.
Recommended
- ‘Crypto Winter’ offers a chance to refresh global ecosystem
- NHS ransomware attack: Hack could take four weeks to fix
- How could Strathclyde Uni research help improve satellite navigation?
Facebook is currently having problems with user retention, according to a recently published Pew Research Center study.
According to researchers, despite Gen Z internet use increasing, the rate at which teens use Facebook is rapidly declining. The study found that only around 32% of teens aged 13-17 use Facebook at all, but in a previous survey from 2014-2015, that figure was 71%, beating out platforms like Instagram and Snapchat.
Meta has been hit before with problems over data privacy, most notably during the Cambridge Analytica scandal.
The British political consulting firm non-consensually accessed data on tens of millions of Facebook to target voters in elections such as the US presidential race, Brexit Referendum and potentially the Scottish Independence vote.
Facebook and Mark Zuckerberg were forced to apologise over the scandal, and both were fined over the scandal. Cambridge Analytica declared bankruptcy.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





