Localmess Exploit - /g/ (#105566037) [Archived: 1166 hours ago]

Anonymous
6/12/2025, 1:35:45 AM No.105566037
websites-app-ID-sharing
websites-app-ID-sharing
md5: 89b448802d9f41792f3a3b517a7d46c6🔍
HAPPENING!!!!

>We disclose a novel tracking method by Meta and Yandex potentially affecting billions of Android users. We found that native Android apps—including Facebook, Instagram, and several Yandex apps including Maps and Browser—silently listen on fixed local ports for tracking purposes.

https://localmess.github.io/
Replies: >>105567348 >>105569310 >>105571198 >>105571483
Anonymous
6/12/2025, 1:42:45 AM No.105566094
i wanna say this is old new by now gwarser made rules to defeat this activity, theres port authority for firefox, chrome implemented block insecure private networks, etc. it is funny that facebook and yandex were still getting away with it i guess.
Anonymous
6/12/2025, 4:54:25 AM No.105567348
>>105566037 (OP)
Do people still use facebook?
Replies: >>105570681
Anonymous
6/12/2025, 9:17:12 AM No.105568922
bump
Anonymous
6/12/2025, 9:20:42 AM No.105568940
Slowpoke
Slowpoke
md5: 486c6c37204e33cf7bd01ae4291ba7c9🔍
breaking news, guys!
Replies: >>105570449 >>105572573
Anonymous
6/12/2025, 10:22:44 AM No.105569310
pepe-003
pepe-003
md5: ca33e12cec5b0213ac37be63562c3cc6🔍
>>105566037 (OP)
im too stoopid to understand what this means
Anonymous
6/12/2025, 1:02:31 PM No.105570407
Oh no, yandex-image-search-enjoyers bros...
Replies: >>105571436
Anonymous
6/12/2025, 1:05:19 PM No.105570419
I posted about this weeks ago and my thread was invaded by facebook shill bots trying to falseflag as anti-brave tinkertroons
Anonymous
6/12/2025, 1:10:05 PM No.105570449
>>105568940
this
Anonymous
6/12/2025, 1:51:42 PM No.105570681
>>105567348
lol
Anonymous
6/12/2025, 2:24:24 PM No.105570907
Do people seriously run native apps?
The browser is right there.
Replies: >>105571229
Anonymous
6/12/2025, 3:12:19 PM No.105571198
1749733927605
1749733927605
md5: 6bca5c415ac59fef68f367ff33ac6b67🔍
>>105566037 (OP)
>using native apps
Anonymous
6/12/2025, 3:17:16 PM No.105571229
>>105570907
They make websites intentionally work like shit on mobile browsers and then perma spam you with banners PLS USE OUR APP SAAR
Replies: >>105571406
Anonymous
6/12/2025, 3:23:19 PM No.105571262
Do people under 60 still use facebook?
Anonymous
6/12/2025, 3:42:46 PM No.105571406
>>105571229
reddit is the worst for this
Anonymous
6/12/2025, 3:46:34 PM No.105571436
>>105570407
...
Anonymous
6/12/2025, 3:52:26 PM No.105571483
>>105566037 (OP)
what are they listening TO? Or do they just harvest everything?
Anonymous
6/12/2025, 4:02:56 PM No.105571579
This is not good. We need to make offtopic threads to slide this post into the archives.
Anonymous
6/12/2025, 4:02:57 PM No.105571580
>Using HTTP requests for web-to-native ID sharing (i.e. not WebRTC STUN or TURN) may expose users browsing history to third-parties. A malicious third-party Android application that also listens on the aforementioned ports can intercept the HTTP requests sent by the Yandex Metrica script and the first, now-unused, implementation of Meta’s communication channel by monitoring the Origin HTTP header.
>We developed a proof-of-concept app to demonstrate the feasibility of this browsing history harvesting by a malicious third-party app. We found that browsers such as Chrome, Firefox and Edge are susceptible to this form of browsing history leakage in both default and private browsing modes. Brave browser was unaffected by this issue due to their blocklist and the blocking of requests to the localhost; and DuckDuckGo was only minimally affected due to missing domains in their blocklist.
Bravejeet W
Anonymous
6/12/2025, 4:05:55 PM No.105571612
Does uBlock's Block Outsider Intruder into LAN prevent this?
Anonymous
6/12/2025, 5:47:38 PM No.105572412
>the Yandex Metrica script transmits data via HTTPS to local ports 29010 and 30103
how can it do HTTPS? to make a request, the browser must deem the certificate valid
do browsers just skip certificate verification for localhost?
>or the the yandexmetrica[.]com domain, which resolves to 127.0.0.1.
I can't see this working over HTTPS though, unless they bundle the private keys for a real cert with their apps
Anonymous
6/12/2025, 6:10:22 PM No.105572573
>>105568940
kek