So, since the loopback interface is shared between all user profiles, I assume this vulnerable is also able to deanonymize you across user profiles. This means we now know of two real cases where the shared loopback interface have been exploited to deanonymize activity across user profiles, rendering the common use case of using separate user profiles for domain isolation useless.
Relevant ticket:
https://github.com/GrapheneOS/os-issue-tracker/issues/4772
GrapheneOS users have been deanonymized by this if either of the following two cases holds:
You have had the Yandex app installed in any user profile at all. In this case your web browsing activity in all user profiles have been tied to your Yandex identity, even if you used Vanadium as your web browser. Only activity from Tor Browser and few other browsers that blocks localhost connections by default will not have been tracked.
You have had the Facebook or Instagram apps installed in any user profile at all, and have had some non-privacy-focused web browser, such as Chrome, installed in any other user profile. In this case your web browsing activity in those non-privacy-focused web browsers will have been tied to your Facebook or Instagram account, even if the web browsing was in another user profile.
Of course, Meta apps installed in separate user profiles can also talk to each other over the loopback interface in just the same way, this time without being hindered by any hardening done in any web browser.
From https://arstechnica.com/security/2025/06/meta-and-yandex-are-de-anonymizing-android-users-web-browsing-identifiers/:
So far, Google has provided no indication that it plans to redesign the way Android handles local port access.
That is unfortunate, since this issue is likely best fixed in AOSP.