A comprehensive analysis of mobile device security has revealed significant risks associated with both mobile VPN applications and pre-installed apps on low-cost Android devices. Zimperium zLabs conducted a large-scale study of 800 free VPN apps available for Android and iOS, uncovering that many of these applications fail to provide genuine privacy protections. Some VPN apps request permissions that are excessive for their intended function, potentially exposing users to unnecessary risks. The research found that several VPN apps leak personal data, undermining the very privacy they are supposed to protect. Outdated and vulnerable code was also identified in a number of these apps, increasing the attack surface for malicious actors. For organizations with bring-your-own-device (BYOD) policies, the use of insecure VPN apps by employees can introduce enterprise-level risks, as sensitive business data may be exposed through these weak points. The study highlights that even popular VPN apps are not immune to these issues, making it critical for both consumers and enterprises to scrutinize the security posture of mobile VPN solutions.
In parallel, another research effort focused on the security of low-cost Android devices, particularly those running Android Go Edition in the African market. Researchers developed an automated framework, PiPLAnD, to extract and analyze APK files from physical devices, revealing that many pre-installed apps on these devices have high-level system access. Unlike apps distributed through the Google Play Store, these pre-installed applications often bypass rigorous security checks, making them potential vectors for malware and privacy violations. The study found that approximately 9% of the pre-installed apps analyzed were leaking sensitive user data, including location, device identifiers, and subscriber information. Data leaks occurred through various mechanisms such as SharedPreferences, device logs, Intents, and network transmissions. Some pre-installed apps were also found to have the capability to silently install additional applications without user consent, further compounding the security risk. In total, 33 apps exhibited this silent installation behavior, which could be exploited to introduce further malicious software onto the device.
Both studies underscore the pervasive nature of mobile security threats, whether originating from third-party VPN apps or manufacturer-installed software on budget devices. The findings highlight the need for organizations to implement robust mobile device management policies and for users to exercise caution when selecting both devices and applications. The risks identified are not limited to individual privacy but extend to organizational security, especially in environments where personal devices are used for work purposes. The research calls attention to the importance of regular security assessments, updates, and the use of trusted sources for both hardware and software. Ultimately, the mobile ecosystem remains a complex and often under-scrutinized component of the broader cybersecurity landscape, requiring ongoing vigilance from both users and enterprises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following publication of the Zimperium research, multiple security news outlets highlighted the findings and warned that insecure free VPN apps could expose consumer and BYOD enterprise data. Coverage emphasized data leakage, surveillance risk, and weak privacy protections across both Android and iOS apps.
The researchers reported outdated and vulnerable components in multiple apps, including three using an OpenSSL version affected by Heartbleed and roughly 1% susceptible to man-in-the-middle attacks. They also found widespread permission abuse, such as requests for location, system logs, microphone, and screen-capture access, along with poor transparency in many iOS apps.
Zimperium zLabs conducted a study of nearly 800 free VPN apps for Android and iOS, examining their security, privacy, and permission practices. The research found many apps provided little real privacy benefit while introducing surveillance and security risks.
Researchers in the Free and Open Communications on the Internet initiative published a report on widely used free Android VPN apps, finding many were insecure and collectively had more than 700 million Google Play downloads. The study said most analyzed apps clustered into three groups ultimately owned by Qihoo 360 and identified privacy and security issues including location tracking, weak encryption, and hard-coded Shadowsocks passwords.
5 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcescworld.com
Open sourcezimperium.com
Open sourcehelpnetsecurity.com
Open sourcetechspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.