in-app browser bridge objects agree with the browser being claimed
No bridge object, or only bridge objects whose owner could have sent this user agent — an iPhone, iPad or Mac user agent for the iOS objects, a UC Browser one for UC's. A user agent naming a brand without that brand's bridge object is not scored: the object ships in one platform's build only, and desktop Edge never carries Edge on iOS's.
What a detector infers
A deployed commercial agent enumerates a short list of window globals that are not web platform features at all. Each is a bridge object that a mobile browser's app injects into the page it displays so that its native side can reach it — Chrome, Firefox, Yandex and Edge on iOS, UC Browser on Android. They arrive from outside the page's control, which is what makes them worth reading against the user agent, a string anything can write.
Only one direction is scored: a bridge object present under a user agent its owner could never send. Every iOS browser is WebKit behind an iPhone or iPad user agent — or a Mac one when an iPad asks for the desktop site — so an iOS wrapper's object under a Windows, Android or Linux user agent means something is rendering the page that the user agent does not admit to. The other direction looks symmetrical and is not.
Each object belongs to one platform's build of a brand, while the brand's user-agent token is shared by all of its builds: desktop Edge carries the same Edge token as Edge on iOS and never defines the iOS object — measured on Edge 153 for Windows, with tracking prevention at Balanced and at Strict, on pages with and without trackers. A brand named without its object is an ordinary build of that brand, not a string on its own, so it is not scored.
Several iOS browsers are also built on one another's web layers, which is why the iOS objects are read by platform rather than by brand.
How to resolve it
These objects come from the application hosting the web view, so no user-agent edit reaches them — and editing the user agent is what produces the mismatch. A profile meant to present as an in-app browser has to actually be one, and a profile meant to present as standalone should not be running inside a wrapper that announces itself.
Nearby checks in Navigator identity
- a second browser target resolves the same timezone as the window
timezone-shared-worker-vs-windowThis audit already compares the window's timezone against a dedicated worker. - the keyboard layout maps the OEM keys the way one real Windows layout would
keyboard-layout-single-originA keyboard layout is not a set of independent key mappings — it is one artifact the operating system hands over whole. - navigator.appVersion is the user agent minus its leading token
appversion-vs-useragentnavigator.appVersion is not an independent fact. In Blink and WebKit it is computed from the User-Agent at read time — literally the UA with… - Firefox's appVersion names the same operating system as its user agent
gecko-appversion-os-vs-uanavigator.appVersion is compared against the user agent by appversion-vs-useragent on Blink and WebKit, where it is the UA minus its first… - the URL parser follows the specification exactly
url-parser-spec-conformanceThe URL specification pins the exact result of a handful of awkward parses, and it pins them for every engine and every operating system… - Trusted Types hands back the branded object its own type demands
trusted-types-value-invariantTrusted Types is a typed API, not a boolean feature flag, and that is the whole of the check. - the user agent on the wire and the one JavaScript reports describe the same browser
ua-wire-vs-navigatorYour user agent is asserted on two channels built by different layers: the network stack writes the header, and the renderer answers… - a Date's own text agrees with the Date's own offset
date-tostring-coherenceA Date's text is not opaque. ECMA-262 defines toString() as toDateString() + " " + toTimeString(), fixes the weekday and month tables to…
Clearcote is a browser built for fingerprint coherence
It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.
This audit takes no position on how Clearcote scores on Navigator identity checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.
See the other checks in Navigator identity — the family webview-wrapper-markers-vs-ua belongs to.
