AUTO-UPDATED

Apple and Google are hosting hundreds of dangerous VPN links — here is why your device is at risk

A recent security audit of mobile VPN apps on the Apple App Store and Google Play Store reveals significant privacy risks, including unencrypted traffic and malicious redirects.

Key Points

  • Researchers identified 339 Android and 188 iOS VPN links using insecure, unencrypted HTTP protocols instead of HTTPS.
  • Popular apps, including Oryx VPN and Stealth Shield VPN, were flagged for failing to enforce secure connection standards.
  • Malicious actors are purchasing expired developer domains to host scareware, fake antivirus popups, and malware-laden redirects.
  • Audit findings uncovered the use of obscured URL shorteners, raw IP addresses, and direct PDF downloads to bypass security scanners.
  • Official store links were found redirecting users to unvetted environments, including abandoned social media pages and third-party messaging platforms.

Why it Matters

These findings demonstrate that official app store vetting processes are insufficient to protect users from sophisticated web-based threats. Consumers must exercise the same level of caution within app stores as they do on the open web to avoid phishing and malware infections.
TechRadar Published by Rene Millman
Read original