Last updated: 2026-10-03
On July 15, 2026, Meta Platforms moved to dismiss the First Amended Complaint in In re Meta Android Privacy Litigation, No. 3:25-cv-04674-RFL (N.D. Cal.), the class action alleging that the Meta Pixel on websites sent a browser cookie to the Facebook and Instagram Android apps through localhost ports. The same day Google, the second defendant, filed its answer. Judge Rita F. Lin had already let most claims proceed in a May 11, 2026 order, and discovery has been open since June 24, 2026. Meta's new motion argues that the order got consent wrong.
What does the complaint allege about Meta localhost tracking?
The First Amended Complaint (FAC), filed June 1, 2026, relies on a June 3, 2025 disclosure by academic researchers, published at localmess.github.io. It alleges (¶¶ 61–64) that the Facebook and Instagram Android apps listened on fixed ports on the phone's loopback interface (127.0.0.1), and that the Pixel script in the phone's browser sent the _fbp first-party cookie value to those ports:
- September to at least October 2024: HTTP requests to port 12387.
- November 2024 to January 2025: WebSocket messages to port 12387.
- Then WebRTC to UDP ports 12580–12585, with "SDP munging" that "inserted the contents of the _fbp cookie into the 'ice-ufrag' field," producing a STUN Binding Request to the localhost port.
- Around May 17, 2025, after a Chrome mitigation: a TURN message "that did not require SDP munging."
The complaint alleges the apps then sent the identifier to Meta's servers, which linked it to the user's account. The researchers' page states that the apps sent _fbp to graph.facebook.com/graphql as a GraphQL mutation (tested on Facebook 515.0.0.23.90 and Instagram 382.0.0.43.84), and that "The Android OS allows any installed app with the INTERNET permission to open a listening socket on the loopback interface (127.0.0.1)." Its update reads: "As of June 3rd 7:45 CEST, Meta/Facebook Pixel script is no longer sending any packets or requests to localhost." In a crawl of the top 100,000 sites, the researchers counted the Pixel's localhost code on 17,223 US sites and 15,677 EU sites. The crawler left the cookie consent window unanswered, and on 13,468 of the US sites (78.2%) the Pixel attempted localhost communication by default when the page loaded, "potentially without user consent," in the researchers' words.
The proposed class (¶ 120, FAC p. 32) is "All Android users in the United States (including its territories) with a Facebook or Instagram account who, between September 1, 2024 and June 2, 2025" had the Facebook or Instagram app installed and visited a website with the Meta Pixel. ¶ 121 pleads a California Subclass. The May order quotes two reactions the complaint recites: a Google representative said the conduct "violate[d] the terms of service for [Google's] Play marketplace and the privacy expectations of Android users," and Mozilla called it "severe violations of our anti-tracking policies" (ECF 120 at 5).
What did the court rule on Meta's first motion to dismiss?
The May 11, 2026 order reads: "Plaintiffs' pen register, unjust enrichment, and negligent misrepresentation claims are DISMISSED with LEAVE TO AMEND. All other claims survive dismissal." On consent, Judge Lin held that "a reasonable user could plausibly read the Privacy Policy to not disclose that Meta would open a backdoor to link their Android web browsing activities to their Meta accounts with absolute certainty" (p. 9). On the computer fraud claim she wrote: "There is a fundamental difference between using known functionality of a system in an unexpected way and employing subterfuge to exploit design flaws that are not broadly known" (p. 16). On Google, the order reads: "Google allegedly designed Android to allow apps to listen in on localhost ports without monitoring, requiring user consent, or imposing restrictions for Incognito browsing sessions" (p. 20). These are rulings on the pleadings, with no finding of fact.
Meta moved to certify the order for interlocutory appeal on the question "Whether a court can narrow an otherwise broad online privacy agreement based on a plaintiff's allegedly reasonable expectations about what the defendant can do," and withdrew the motion on June 30, 2026 (ECF 133, docket).
| Claim | Defendant | May 11, 2026 order (ECF 120) | Status after the FAC |
|---|---|---|---|
| Intrusion upon seclusion; California Constitution | Meta | Survived | Challenged again |
| Wiretap Act, 18 U.S.C. § 2511(1); CIPA §§ 631, 632, 635 | Meta | Survived | Challenged again; Meta argues the matching was a "subsequent use" |
| CIPA § 638.51 (pen register) | Meta | Dismissed with leave to amend | Repleaded with IP address allegations (FAC ¶¶ 26–27, 37) |
| CDAFA, Cal. Penal Code § 502 | Meta | Survived | Challenged again |
| Unjust enrichment | Meta | Dismissed with leave to amend | Dropped (ECF 136) |
| Negligence | Survived | Answered (ECF 137) | |
| Negligent misrepresentation | Dismissed with leave to amend | Re-alleged to preserve appeal rights |
Sources: ECF 120, ECF 136, ECF 137 at 30.
What does Meta argue in the new motion, and what did Google admit?
Meta's motion opens: "This Court previously allowed most of Plaintiffs' claims to survive dismissal. Respectfully, that order was wrong." Its central argument is consent: "Plaintiffs consented to the very matching they now complain about. That consent defeats every claim." On the repleaded pen register claim, Meta argues the functionality did not record "routing information reflecting who Plaintiffs communicate with." It puts the conduct at "a window of roughly nine months" (p. 10). The docket lists the plaintiffs' opposition (ECF 147, 2026-08-12) and Meta's reply (ECF 151, 2026-09-02); neither is on RECAP as of October 3, 2026.
Google's answer states at ¶ 5: "Google admits that Meta's conduct as alleged in the Complaint violated Android's sandboxing protocols. Google denies that the conduct at issue constituted a 'breach' of Android or that Google impaired any user's ability to maintain online privacy." At ¶ 2 Google "denies any allegation that Android contained a vulnerability." Its first affirmative defense attributes any harm to "the independent, intentional, and concealed conduct of Meta," and its second seeks to reduce any award against Google in proportion to Meta's fault. The admission is a co-defendant's pleading about Android's rules.
California's SB 690 (Chapter 976) bears on the pen register count: from January 1, 2027 it makes § 638.51 claims over website and app conduct an Attorney General action, and applies to pending claims in actions commenced in the two years before that date. This case was filed in 2025, inside that window; how the clause applies to a count repleaded in 2026 is for the court.
What happens next in In re Meta Android Privacy Litigation?
Plaintiff Bert Velilla voluntarily dismissed his claims on July 22, 2026 (ECF 141); on August 18, 2026 the court referred the case to a magistrate judge for discovery (ECF 149). A text-only Clerk's Notice of September 18, 2026 (ECF 154, on the PacerMonitor copy of the docket) reads: "Motion hearing re: [136] Motion to Dismiss for oral argument on 09/22/2026 is VACATED. Pursuant to Local Rule 7-1(b), Court will decide the motion on the papers." As of October 3, 2026 the motion is undecided; that notice is the last entry on the CourtListener docket and the PacerMonitor copy. The minute entry for the June 24, 2026 case management conference (ECF 128) sets the plaintiffs' class certification motion for October 15, 2027 and the hearing for February 29, 2028. Rodriguez v. Google, another app data class action in the same district, went from class certification to a jury verdict.
The current behavior changes page for apps targeting Android 17 introduces the ACCESS_LOCAL_NETWORK runtime permission, which it says "prevents malicious apps from exploiting unrestricted local network access for covert user tracking and fingerprinting." A February 2026 version of the same page described a separate install-time permission, USE_LOOPBACK_INTERFACE, under which, for apps targeting Android 17 or higher, cross-app loopback traffic is "blocked by default" unless both the sending and the receiving app declare it. The current page, last updated October 1, 2026, omits it. The behavior changes page for all apps now states a narrower rule: "Beginning with Android 17, cross-profile loopback traffic is no longer permitted by default. Loopback traffic within the same profile is not affected." The complaint's setup, a browser and an app in one profile, falls under the second sentence. The Android 17 release notes leave open whether Google still plans a cross-app loopback restriction.
What do a scan and a capture of the Facebook and Instagram apps show?
CanITrustThat (CITT) has static scans of Facebook 544.0.0.42.272 (analyzed 2026-01-22) and Instagram 414.0.0.40.83 (analyzed 2026-01-31). Both builds postdate the class period; both pages are static analysis only. The scan lists every permission the manifest declares, INTERNET included. An Android rule flags a loopback URL or address in the dex code on port 29009, 29010, 30102 or 30103, the ports the researchers documented for Yandex, the only other company they found using this side channel. The Meta ports 12387 and 12580–12585 fall outside that rule; finding them takes reading the decompiled code. Both show presence in the binary. Transmission takes a capture that records a browser on the same device loading a page with the Pixel, an HTTP request or WebRTC packet to 127.0.0.1 that contains the _fbp value, and the app's next request to Meta. The behavior ended on June 3, 2025, per the researchers, so a 2026 capture tests current builds only.
When I scan an app, every static finding cites its file and line and every traffic finding cites its capture. What a scan checks and the limits of a scan are on the methodology page. I run app tracking investigations for lawyers and the researchers working with them, on one app or a list in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.