Skip to main content

Security researchers warn against using shady VPN Android apps

Maksim Kabakou / 123RF
If you’ve ever needed to conduct business over the internet somewhat privately on your phone, a virtual private network — or VPN, for short — is an excellent way to go about it. It’s basically an encrypted third-party middleman that sits between you and the wider internet, protecting your data from prying eyes.

And its practically foolproof — even if a hacker were to penetrate the “tunnel,” so to speak, they would struggle to read the data within. But to use a virtual private network, you need an app, and not all apps are as secure as the virtual private network itself.

Security researchers at CSIRO’s Data 61, the University of New South Wales, and UC Berkeley studied 283 VPN apps for Android available from the Google Play Store. A whopping 38 percent of the apps on the Google Play Store that were tested contained some form of malware, adware, trojan, or spyware, while 67 percent featured at least one third-party tracking library. As many as 82 percent requested permissions to access sensitive user data, including text messages and call logs.

The researchers categorized the “worst offenders” — apps with an excessive amount of malware — in a top-ten chart.

And to make matters worse, many fell short of delivering the anonymity they promised. Around 18 percent of the VPN apps didn’t encrypt traffic, and 16 percent routed traffic through other users of the same app rather than a dedicated server. And as many as 66 percent leaked traffic, which the researchers noted could “ease online tracking activities” performed by unscrupulous Wi-Fi hot spot administrators and “surveillance agencies.”

Worryingly, more than 25 percent of the apps received at least a 4-star rating. “According to the number of installs of these apps, millions of users appear to trust VPN apps despite their potential maliciousness. In fact, the high presence of malware activity in VPN apps that our analysis has revealed is worrisome given the ability that these apps already have to inspect and analyze all user’s traffic with the VPN permission,” the researchers wrote.

Ultimately, the survey’s authors recommend “looking before you leap,” in a sense — in other words, researching the VPN apps you’re considering and ensuring they act and behave as advertised. Be especially wary of free apps, they say. Stick to well-known companies that are transparent about their practices. And if an app requests access to sensitive information during the installation process for no good reason, it’s probably best to get rid of it.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
How one special feature changed my smartphone photos forever
A person holding the OnePlus 12.

I don’t usually mess around with Pro modes in smartphone camera apps much. I’m not a “pro,” so they rarely seem relevant, and the combination of an effective auto mode and a great editing platform usually means I end up with a photo I’m pleased with anyway.

But that all changed when I tried Master Mode on the OnePlus 12. Yes, it’s a Pro mode in disguise, but it has an unusual and quite specific feature set that has helped me create photos I love and furthered my own photographic style far more than most other phones I’ve used recently.
Personal photographic style

Read more
The best Android tablets in 2024: the 11 best ones you can buy
OnePlus Pad with official Stylo pencil stylus on a wooden table.

Tablets may not be the hot new thing in 2024, but they're still excellent machines for streaming movies, playing games, or getting work done on the go. And while it seems like the best iPads dominate most of the tablet market, there are still plenty of excellent Android tablet options for consideration if you don't want to be locked in Apple's walled garden.

Whether you want an ultra-premium and superpowerful option, or something more affordable and compact, the Android tablet market has something for everyone. No matter your budget or spec preferences, here are the best Android tablets you can buy in 2024.

Read more
The best Samsung Galaxy Watch in 2024: Which one should you buy?
The Samsung Galaxy Watch 6 Classic and Galaxy Watch 5 Pro, side by side on a persons wrist.

While the openness of the Android ecosystem means there’s no shortage of options to choose in terms of smartwatches, Samsung’s Galaxy Watch family leads the pack by a wide margin.

The Galaxy Watch 6 marks the wearable’s fifth generation (there was never a Galaxy Watch 2), which means the line has had plenty of time to evolve and mature. Samsung’s decision to embrace Wear OS two years ago and expand the lineup in new directions with an adventurous “Pro” model and the return of the much-loved rotating bezel means that there’s now a Galaxy Watch for just about everyone.

Read more