A recent security audit of mobile VPN apps on the Apple App Store and Google Play Store reveals significant privacy risks, including unencrypted traffic and malicious redirects.
Key Points
- Researchers identified 339 Android and 188 iOS VPN links using insecure, unencrypted HTTP protocols instead of HTTPS.
- Popular apps, including Oryx VPN and Stealth Shield VPN, were flagged for failing to enforce secure connection standards.
- Malicious actors are purchasing expired developer domains to host scareware, fake antivirus popups, and malware-laden redirects.
- Audit findings uncovered the use of obscured URL shorteners, raw IP addresses, and direct PDF downloads to bypass security scanners.
- Official store links were found redirecting users to unvetted environments, including abandoned social media pages and third-party messaging platforms.