Skip to main content

Security researchers warn against using shady VPN Android apps

If you’ve ever needed to conduct business over the internet somewhat privately on your phone, a virtual private network — or VPN, for short — is an excellent way to go about it. It’s basically an encrypted third-party middleman that sits between you and the wider internet, protecting your data from prying eyes.

And its practically foolproof — even if a hacker were to penetrate the “tunnel,” so to speak, they would struggle to read the data within. But to use a virtual private network, you need an app, and not all apps are as secure as the virtual private network itself.

Recommended Videos

Security researchers at CSIRO’s Data 61, the University of New South Wales, and UC Berkeley studied 283 VPN apps for Android available from the Google Play Store. A whopping 38 percent of the apps on the Google Play Store that were tested contained some form of malware, adware, trojan, or spyware, while 67 percent featured at least one third-party tracking library. As many as 82 percent requested permissions to access sensitive user data, including text messages and call logs.

The researchers categorized the “worst offenders” — apps with an excessive amount of malware — in a top-ten chart.

And to make matters worse, many fell short of delivering the anonymity they promised. Around 18 percent of the VPN apps didn’t encrypt traffic, and 16 percent routed traffic through other users of the same app rather than a dedicated server. And as many as 66 percent leaked traffic, which the researchers noted could “ease online tracking activities” performed by unscrupulous Wi-Fi hot spot administrators and “surveillance agencies.”

Worryingly, more than 25 percent of the apps received at least a 4-star rating. “According to the number of installs of these apps, millions of users appear to trust VPN apps despite their potential maliciousness. In fact, the high presence of malware activity in VPN apps that our analysis has revealed is worrisome given the ability that these apps already have to inspect and analyze all user’s traffic with the VPN permission,” the researchers wrote.

Ultimately, the survey’s authors recommend “looking before you leap,” in a sense — in other words, researching the VPN apps you’re considering and ensuring they act and behave as advertised. Be especially wary of free apps, they say. Stick to well-known companies that are transparent about their practices. And if an app requests access to sensitive information during the installation process for no good reason, it’s probably best to get rid of it.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Amazon’s Marvel-themed ‘Pro’ kids tablet is marked down to just $95 today
A closer look at a Marvel-themed Amazon Fire HD 8 Kids Pro tablet.

While we don't want our little ones glued to a screen all the time, there's no doubt that tech is a part of our kids' lives right now. If we're going to integrate tech into kids lives, we may as well get the best. This deal on an Amazon Fire HD 8 Kids Pro tablet gets you a Marvel-themed tablet for just $95, saving you $55 off of the typical $150 price point. This tablet is designed with kids' safety and well-being in mind -- and it just looks cool. Tap the button below to see the tablet and its features yourself, or keep reading to see why this is one of the best tablets for kids you can buy at a discounted price today.

Why you should buy the Amazon Fire HD 8 Kids Pro tablet
The Amazon Fire HD 8 Kids Pro tablet is an accessible 8-inch tablet that comes with a 2-year guarantee in case it ever breaks, 6 months of free Amazon Kids+ for ad-free and age-appropriate content and smart activities, and simple parental controls. This tablet is designed for kids up to 12 years old, so its web browser has built-in guardrails to protect against weird content getting on screen.

Read more
Nothing’s CEO just told us when to expect the Nothing Phone 3
Nothing Phone 3a

There has been a lot of speculation around the Nothing Phone 3, but in an Ask Me Anything thread on X, Nothing's CEO just confirmed its launch window: quarter three of 2025. Considering today is not April Fool's Day and Carl Pei runs the company, we can't think of a more reliable source for information on this. The launch window also lines up with previous releases; the Nothing Phone and Phone 2 both launched in July, and it looks like the third in the series is likely to follow.

The Nothing Phone 3 will be the company's third release this year, following the Nothing Phone 3a and 3a Pro. Nothing also revealed images of the CMF Phone 2 Pro with a new, redesigned look, and more information on the handset will be shown on April 28 at its global launch event.

Read more
New YouTube Music shortcut lets you quickly control volume levels
Watching playlists on YouTube Music.

YouTube Music just rolled out a small but surprisingly useful change that makes it way easier to manage your listening experience, especially if you're someone who's constantly adjusting the volume between tracks. As part of its latest update, the app now lets you double-tap the “Volume normalizer” setting directly from the Now Playing screen instead of burying it in the settings menu. That should make it a bit easier to accomplish two things: not damaging your eardrums and liking songs.

Here’s how it works, according to Android Authority. When you're playing a song, just tap the three-dot menu in the top right corner of the Now Playing screen. You’ll see a new option called “Consistent volume.” Tap that and it’ll toggle volume normalization on or off right there, with no digging through submenus required. It's a pretty straightforward option.

Read more