281 Popular VPN Apps from the Google Play Leaks Sensitive Data, Transfers Data Unencrypted

A security study of 281 popular Android VPN apps revealed that many transmit data without encryption and leak user traffic. These vulnerabilities could allow attackers to intercept sensitive information or redirect users to malicious servers.
Why it matters
VPNs are often used for privacy, but these findings suggest that many popular apps actually increase security risks for billions of users.
A new security study has found serious privacy and security issues in 281 popular Android VPN applications available on the Google Play Store.
Researchers discovered that dozens of these apps transfer data without encryption, leak user traffic outside the VPN tunnel, and send device identifiers to advertising and tracking services.
The research team from multiple universities developed a framework called MVPNalyzer to test how Android VPN apps handle network traffic, configuration files, and user data. VPN apps hold a privileged position on smartphones because they can intercept and route traffic from other applications.
Users often install them to avoid surveillance, bypass censorship, or protect activity on untrusted Wi-Fi networks. However, the study shows that many apps fail to provide even basic protections.
Researchers tested 281 operational free VPN apps collected from Google Play search results and the VPN Proxy & Tools category.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in