Skip to content
All fingerprint checks
Navigator identity

in-app browser bridge objects agree with the browser being claimed

Pim· Clearcote Research 2 min readCheck id webview-wrapper-markers-vs-ua

No bridge object, or only bridge objects whose owner could have sent this user agent — an iPhone, iPad or Mac user agent for the iOS objects, a UC Browser one for UC's. A user agent naming a brand without that brand's bridge object is not scored: the object ships in one platform's build only, and desktop Edge never carries Edge on iOS's.

What a detector infers

A deployed commercial agent enumerates a short list of window globals that are not web platform features at all. Each is a bridge object that a mobile browser's app injects into the page it displays so that its native side can reach it — Chrome, Firefox, Yandex and Edge on iOS, UC Browser on Android. They arrive from outside the page's control, which is what makes them worth reading against the user agent, a string anything can write.

Only one direction is scored: a bridge object present under a user agent its owner could never send. Every iOS browser is WebKit behind an iPhone or iPad user agent — or a Mac one when an iPad asks for the desktop site — so an iOS wrapper's object under a Windows, Android or Linux user agent means something is rendering the page that the user agent does not admit to. The other direction looks symmetrical and is not.

Each object belongs to one platform's build of a brand, while the brand's user-agent token is shared by all of its builds: desktop Edge carries the same Edge token as Edge on iOS and never defines the iOS object — measured on Edge 153 for Windows, with tracking prevention at Balanced and at Strict, on pages with and without trackers. A brand named without its object is an ordinary build of that brand, not a string on its own, so it is not scored.

Several iOS browsers are also built on one another's web layers, which is why the iOS objects are read by platform rather than by brand.

How to resolve it

These objects come from the application hosting the web view, so no user-agent edit reaches them — and editing the user agent is what produces the mismatch. A profile meant to present as an in-app browser has to actually be one, and a profile meant to present as standalone should not be running inside a wrapper that announces itself.

Anatomy of a browser fingerprint: every signal, and why they must agree

Nearby checks in Navigator identity

See all 39 checks in Navigator identity
Who builds this test

Clearcote is a browser built for fingerprint coherence

It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.

This audit takes no position on how Clearcote scores on Navigator identity checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.

See the other checks in Navigator identity — the family webview-wrapper-markers-vs-ua belongs to.