https://www.eff.org/deeplinks/2025/06/protect-yourself-metas-latest-attack-privacy
#Meta’s #trackingpixel was secretly communicating with Meta’s apps on #Android devices. This violates a fundamental security feature #sandboxing of #mobileOS that prevents #apps from communicating with each other. Meta got around this restriction by exploiting #localhost, a feature meant for developer testing. This allowed Meta to create a hidden channel between mobile browser apps and its own apps.