Of the four Chinese browsers offering incognito mode (Baidu Searchbox, UC Browser, QQ Browser, Redmi/Mi), all four continue to leak PII and three continue to transmit full browsing activity including URLs; UC Browser specifically sends data during incognito sessions encrypted with hardcoded AES/CBC key "Ine34@32b#jeRs2h" and a zero initialization vector to crash-upload endpoints. Incognito mode in these browsers provides no protection against vendor-side or on-path surveillance and creates false privacy expectations for circumvention tool users.
From 2025-rodriguez-revisiting — Revisiting BAT Browsers: Protecting At-Risk Populations from Surveillance, Censorship, and Targeted Attacks
· §4.2
· 2025
· Free and Open Communications on the Internet
Implications
Circumvention tool documentation must explicitly state that Chinese browser incognito modes do not prevent browsing activity exfiltration; incognito is not a substitute for a privacy-respecting browser when used alongside a VPN.
PWA-based circumvention or encrypted-chat tools accessed via Chinese browsers in incognito mode should warn users that page titles and URLs are still logged to vendor servers, and consider redirecting users to a recommended browser before presenting sensitive functionality.