I found this website on reddit that is intended to be opened using inapp browsers and tells you what JS is injected into the browser (to the best of its ability)
that’s the site made by the person who wrote the original blog post this article is based off of !
I'm confused, how do I even get to the in app browser? If someone links me something on tiktok?
Exactly.
Is anyone really shocked by this?
So does Instagram
Yep. There was a report about how all in-app browsers can do this, and that FB/IG/Twitter/etc. all did it. But, of course, saying TikTok does it gets the clicks.
Reports I read said that while they all inject code, TikTok was the worst, injecting code that intercepts every key press and click.
On iOS at least there are more restrictions of using SafariViewController vs WebView. I could imagine Apple making a policy change to force towards that stricter surface.
I think Twitter does the same with their in-app browser. Is there any way to configure to use your regular browser instead?
For Twitter it's Settings and Privacy > Accessibility, display and languages > Display > Web browser > Use in-app browser
This is on Android, I'm not sure if it's the same on iOS
Use the website rather than the app. Links from the web app will open in your regular browser.
This isn't surprising at all, but also it's a bit alarmist. Who ever uses the in-app browser other than to follow a quick link that usually opens up a native app from there (like YouTube, for example)? Seems like nothing to stress about really, esp. if you're already okay being on these apps to begin with.
Any Safari extension could theoretically do the same, even if it is available on the AppStore. I doubt app review does security audits of extensions they approve.
Safari content blockers are passive and don't run arbitrary code on pages.