Facebook sued for allegedly spying on users via in-app web browser


Meta is being sued for allegedly gathering personally identifiable information (PII) on its Facebook and Instagram users without telling them.
As per the lawsuit, the problem lies in how the company’s Facebook and Instagram platforms handle internet links on an iOS device. Both apps have their own embedded internet browsers (opens in new tab), the WKWebView, which render the pages when a user clicks on a link (as opposed to opening the links in, say, Safari, or Chrome).
On the user’s side, clicking a link would make it seem as if the app opened the page, rather than as if it was opened in a separate app. However, the plaintiffs say that the browser also injects JavaScript code that gathers data – something other browsers wouldn’t be able to do.
Personally identifiable information
“When users click on a link within the Facebook app, Meta automatically directs them to the in-app browser it is monitoring instead of the smartphone’s default browser, without telling users that this is happening or they are being tracked,” the lawsuit says.
“The user information Meta intercepts, monitors and records includes personally identifiable information, private health details, text entries, and other sensitive confidential facts.”
The case was boosted by previous findings from cybersecurity researcher Felix Krause, who raised the issue in August 2022.
When Krause published his findings, Meta responded by saying the code injection was done to respect user privacy (opens in new tab) choices.
“We intentionally developed this code to honor people’s App Tracking Transparency (ATT) choices on our platforms,” a Meta spokesperson told The Register. “The code allows us to aggregate data before it is used for targeted advertising or measurement purposes.”
The plaintiffs, Gabriele Willis and Kerreisha Davis, do not dispute Apple’s data gathering practices, just the fact that it kept quiet about it.
“Meta fails to disclose the consequences of browsing, navigating, and communicating with third-party websites from within Facebook’s in-app browser – namely, that doing so overrides their default browser’s privacy settings, which users rely on to block and prevent tracking,” it says in the complaint.
“Similarly, Meta conceals the fact that it injects JavaScript that alters external third-party websites so that it can intercept, track, and record data that it otherwise could not access.”
The company rejected the claims, with a spokesperson saying: “These allegations are without merit and we will defend ourselves vigorously.”
“We have carefully designed our in-app browser to respect users’ privacy choices, including how data may be used for ads.”
- These are the best VPNs (opens in new tab) around
Via: The Register (opens in new tab)
Audio player loading… Meta is being sued for allegedly gathering personally identifiable information (PII) on its Facebook and Instagram users without telling them. As per the lawsuit, the problem lies in how the company’s Facebook and Instagram platforms handle internet links on an iOS device. Both apps have their own…
Recent Posts
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010