Study Finds Major Security and Privacy Flaws in Popular Free Android VPN Apps

A new study reveals major security and privacy flaws in popular free Android VPN apps. Learn the risks, key findings, and how to choose a safer VPN.

Researchers from the University of Michigan, the University of New Mexico, and the Indian Institute of Technology Delhi tested 281 of the most popular free VPN applications on the Google Play Store using a new auditing framework called MVPNalyzer and found that many failed to provide the basic privacy and security protections that users expect from a VPN service. The apps identified with at least one significant issue have collectively been installed more than 2.4 billion times. 

The study found several fundamental security weaknesses. 29 apps leaked user traffic outside the encrypted VPN tunnel, including DNS requests that reveal the websites a user visits, while 61 apps transmitted some data in plain text that could be read by anyone monitoring the same network. The most serious finding involved five apps that downloaded their configuration files without encryption, creating a tunnel hijacking risk in which an attacker on the same network could modify the configuration and redirect the VPN connection to a server under the attacker’s control. 

The researchers disclosed the tunnel hijacking vulnerability to the affected developers. After re-testing the latest versions, they found that VPN Pro and Hexa VPN had fixed the issue, while BambooVPN, Free VPN and 101 VPN remained vulnerable. The researchers also observed that the developer responses did not always match the eventual fixes implemented. 

Additional testing showed that 24 apps leaked DNS traffic, exposing users’ browsing destinations to the local network; six apps leaked full browsing traffic outside the VPN tunnel, and four apps operated tunnels with no encryption at all. Some applications suffered from more than one of these problems, meaning that users could be exposed through multiple channels simultaneously. 

The study also examined whether VPN apps attempted to conceal the fact that they were VPNs. 169 apps made no effort to disguise their traffic, making it easy for network operators, internet providers or government censors to identify and block them. The researchers noted that many of these apps advertised features such as bypassing restrictions or unlocking blocked content despite providing no meaningful traffic obfuscation. 

Privacy concerns extended beyond traffic leaks. 76 apps transmitted the device’s Advertising ID, a unique identifier used for tracking across applications, and 246 apps contacted known advertising and tracking servers. Many also collected information such as the phone model, operating system version and screen size, while one app transmitted the device’s exact GPS coordinates. The researchers noted that these data points can be combined to create a unique fingerprint capable of identifying a specific device. 

Analysis of OpenVPN configuration files from 108 apps revealed further weaknesses. Only one app followed all the security best practices measured in the study. About 89% relied on a single authentication method instead of combining a password and a certificate; nearly one in five used weak or outdated encryption algorithms such as Blowfish or Triple DES, and a few disabled encryptions entirely by setting the tunnel’s data cypher to “none.” 

The researchers concluded that many of these problems appeared to result from poor maintenance and insufficient screening by app-store review processes. Several of the affected applications ranked highly in Play Store search results and displayed trust indicators such as Google’s “Verified” badge, which is intended to signal that an app has undergone a security assessment. 

READ MORE -> Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking | The Hacker News  

MINI HEADLINES 

AI cybersecurity defense system blocking a crypto wallet breach - Free Stock Photo by William David on Stockvault.net
  • Gujarat Establishes Departmental Data Committee to Protect Farmers’ Data 

The Gujarat government has established a Departmental Data Committee (DDC) within the Agriculture, Farmers Welfare and Cooperation Department to safeguard the personal, financial and agricultural data of farmers in line with the Digital Personal Data Protection Act, 2023 (DPDP Act). 

The committee will ensure that farmers data is used only with their consent and in compliance with applicable regulations. It will oversee the secure, scientific and transparent management of data across the Agriculture Department, its associated boards, corporations and agricultural universities. The committee will ensure compliance with the DPDP Act and other government regulations to prevent unauthorised use and provide legal protection for data security.  

A major focus of the framework is Consent Management, under which farmers data will be accessed only with their approval. A secure, auditable and traceable record of all consent will be maintained, and any violation will be reported to the State Data Authority (SDA). The DDC will continuously monitor data for security incidents and breaches, reporting them immediately to the State Chief Data Officer and other relevant authorities to enable a rapid response. 

Access to secure and authenticated data is expected to support improved research and informed decision-making in agriculture, enabling more effective and targeted farmer welfare schemes. The framework aims to keep farmers personal, banking and sensitive information secure, prevent misuse, unauthorised access and cyber threats, and improve transparency, efficiency and accuracy in the distribution of agricultural subsidies, crop insurance, disaster relief and other government assistance. 

READ MORE -> Gujarat forms Departmental Data Committee to protect farmers’ data | The News Mill  

  • Supreme Court Restricts Broad Use of Geofence Warrants to Protect Cellphone Location Privacy 

The U.S Supreme Court has limited the use of broad “geofence warrants,” which allow law enforcement to obtain cell phone location data from many users in a specific area, including people not connected to a crime. The Court held that obtaining such location data involves the Fourth Amendment’s protection against unreasonable searches and seizures. The Court stated that individuals have a reasonable expectation of privacy in records showing their cell phone locations, even when that data is held by a third-party technology company. 

The Court described location information as a “personal journal” of a user’s movements and said it should receive the same protection as private materials such as emails, photographs, and documents. As a result of the ruling, law enforcement authorities must obtain a more narrowly tailored warrant before accessing location data covering a large group of users in a particular area.  

Google has since changed its geofence data practices by storing location information on users’ phones rather than in a separate database. However, other companies that retain location data may also be affected by the ruling. 

READ MORE -> Supreme Court limits use of 'geofence warrants' amid cellphone data privacy concerns | abc news  

  • Reputational Risk Emerges as the Top Concern for India’s Fintech Sector 

A new industry report has identified reputation and brand damage as the most significant risk facing India’s fintech sector, ranking ahead of infrastructure disruptions, competition, data privacy, cyberattacks and regulatory issues. According to the Fintech Barometer 2026, released by the Fintech Association for Consumer Empowerment and Grant Thornton Bharat, nearly 59 per cent of surveyed fintech companies classified reputational risk as a high-severity concern. 

Data access, privacy and protection received a severity score of 6.6, with 49 per cent of respondents rating it as a high risk. Cybersecurity, technology and business continuity, along with regulatory and governance risks, were each rated at 6.5. Artificial intelligence, machine learning and model-related risks ranked lowest among the nine categories, with an average severity score of 5.8. However, the report noted that AI-related risks involving governance, privacy, cybersecurity and model failures are expected to become more important as fintech companies increasingly use AI for underwriting, fraud detection, customer engagement and decision-making. 

The findings are based on a survey of 39 FACE member fintech companies operating in lending, payments, regulatory technology, collection technology and techfins. Participants rated the nine risks on a scale of one to 10. The report stated that India’s fintech sector is entering a stage where trust, governance and operational resilience are becoming as important as innovation for sustainable growth and stronger governance, customer trust and greater collaboration across the ecosystem will shape the next phase of growth in India’s fintech industry. 

READ MORE -> Reputation biggest risk for Indian fintechs, ahead of cyber, AI: Report | Business Standard   

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands