Independent research found systemic privacy gaps in Chinese smart home iOS apps, particularly around bystander privacy (people captured by cameras/mics who are not the account owner). A review of 49 apps in Apple’s mainland China App Store reported frequent mismatches between App Store privacy labels, privacy policies, and in-app settings, alongside broad collection of sensitive data and permissions (e.g., location, camera, microphone, contacts, Bluetooth, notifications) and identity-linked registration requirements (phone number + SMS verification).
Separately, a technical proof-of-concept demonstrated how Android’s AccessibilityService can be abused as a “single-toggle” path to near-total device control without rooting or exploiting a vulnerability. The write-up describes rapid, silent enablement/abuse patterns that can lead to permission-like capabilities (screen capture, keylogging, gesture injection, data access, and remote control via a browser-based C2), highlighting how this legitimate accessibility feature is leveraged by stalkerware/monitoring ecosystems and why existing coverage often understates the practical impact.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
The study reported that Apple privacy labels often underreported tracking and user-linked data collection, and that disclosures about law-enforcement or public-security data sharing lacked corresponding user notification features. Researchers recommended stronger bystander-focused controls and better transparency.
A research study reviewed 49 smart home apps in Apple’s App Store in mainland China and found that protections for bystanders were largely absent. The analysis identified broad sensitive data collection and recurring inconsistencies between privacy policies, in-app controls, and App Store privacy labels.
The same research described a pivot in which an app targeting SDK 28 can execute binaries from its app data directory, download a Termux-compatible Linux userland, and run tools such as nmap, python, and openssh inside the app sandbox with only INTERNET permission. The author framed this as a design-level Android platform risk that supports commercial stalkerware-style abuse.
A blog post described a proof-of-concept Android implant that can achieve near-total device control after a user enables a malicious app’s AccessibilityService, without root, exploits, or zero-days. The author said the PoC used documented Android APIs to support capabilities such as permission granting, contextual keylogging, remote touch control, screenshot capture, stealth overlays, and persistence techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcechocapikk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.