What was the 'localhost' tracking bug Meta got caught using?
Academic researchers disclosed on June 3, 2025 that Meta Pixel, embedded on roughly 5.8 million websites, sent tracking cookies through the device's own loopback interface to the Facebook and Instagram apps, silently linking web browsing to a user's logged-in identity — bypassing Incognito Mode, cookie-clearing, and Android's app sandbox. Meta halted it the same day Google shipped countermeasures.
Answered in
How Meta Actually Tracks You: Inside Facebook, Instagram and WhatsApp's Surveillance MachineA localhost backdoor beat Incognito Mode. Instagram DMs lost encryption entirely. Here's how Meta's tracking machine really works, fact by fact.
Read the full analysisOther questions this article answers
More ai & society questions
- Does Chrome send what I type before I even press enter?
- Can Google know my location without me opening Google Maps?
- What is real-time bidding and why does it expose my data hundreds of times a day?
- Can the government get my Google data without a warrant?
- Does Google train Gemini directly on my Gmail and Photos?
- Does Facebook track you even if you don't have an account?
- Does clearing 'Off-Facebook Activity' actually delete your data?
- Are Instagram DMs end-to-end encrypted in 2026?
Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the AI & Society beat.