It's effectively malware—this article has some more detail: https://arstechnica.com/security/2025/06/meta-and-yandex-are...
Basically, they created a channel between the browser and a localhost webserver running in their native apps, by abusing the ability to set arbitrary metadata on WebRTC connections. That way, they were able to exfiltrate tracking cookies out of the browser's sandbox to the native app, where they could be associated with your logged-in user identity.