When clicking a link in big-tech mobile apps, those will generally open withinin a custom in-app-browser (IAB) so the users won't leave the app and miss them yummy retention time.
Additionally, app makers sometimes also inject JavaScript files into their IABs. In the case of Instagram they will offer you to store passwords with your Meta account when logging into third party websites while inside of their IAB.
This page will check, if any unexpected scripts were injected. Open this URL https://romanzipp.com/iab in the IAB of the app you want to test. This can be achieved by storing the URL anywhere, where it's made clickable. For example:
Have you found a website that injects scripts into their IAB? Please tell me! See landing page for contact options. https://romanzipp.com