So VerizonWireless is allowing third-party sites to correlate all HTTP traffic from one device to a single identity, even if you've taken explicit steps (like 'incognito' mode) to try to thwart this, and even if the mobile OS has compartmentalized apps away from seeing each others' identity data/cookies.
Only HTTPS and VPN traffic is immune, and as far as I've been able to find out, there is no way to opt-out. (None of the VerizonWireless privacy settings stop the header from being injected.)