“This web-to-app ID sharing method bypasses typical privacy protections such as clearing cookies, Incognito Mode and Android’s permission controls.”

Facebook and Instagram sat on Android localhost ports listening for the Meta Pixel in your browser. That tied your web browsing to your logged-in account, even in incognito, on more than 17,000 sites. Most of them ran it with no consent given. Meta pulled the code the day it was exposed and called it a miscommunication with Google.