Android apps with nearly 15 million downloads could put users’ data at risk, more than 1,500 security risks detected

Android apps with nearly 15 million downloads could put users’ data at risk, more than 1,500 security risks detected
AI-generated image for representation purpose

Android users, beware! Several popular mental health apps with around 14.7 million downloads on Google Play Store may be putting your data at risk. According to research by Oversecured (via Bleeping Computer), multiple mental health apps, including AI-based therapy chatbots, contain vulnerabilities that are capable of exposing private therapy conversations, mood logs and medical details. In one case, researchers found more than 85 medium- and high-risk security flaws in a single app. As per the report, some of these apps – with millions of downloads globally – claim to offer privacy and encryption on the vendor’s servers. “Mental health data carries unique risks. On the dark web, therapy records sell for $1,000 or more per record, far more than credit card numbers,” says Sergey Toshin, founder of mobile security company Oversecured.

A total of 1,575 security flaws detected

In its research, Oversecured scanned ten mobile apps advertised as tools that can help with various mental health problems. During the research, the organisation uncovered a total of 1,575 security vulnerabilities (54 rated high-severity, 538 medium-severity, and 983 low-severity). Though not critical, these vulnerabilities can be exploited to intercept login credentials, spoof notifications, HTML injection, or to locate the user.

5 Features Android borrowed From iPhone!

“These apps collect and store some of the most sensitive personal data in mobile: therapy session transcripts, mood logs, medication schedules, self-harm indicators, and in some cases, information protected under HIPAA,” the researchers note.

How the flaws are misused

According to the report, some apps improperly handle links and commands from outside sources. This could allow attackers to access internal parts of the app that are not meant to be exposed, including areas that handle login tokens or session data. In simple terms, a hacker could trick an app into opening protected sections and gain access to therapy records.One therapy app with over a million downloads allegedly uses Intent.parseUri() on an externally controlled string and launches the resulting messaging object (intent) without validating the target component. This allows an attacker to force the app to open any internal activity, even if it is not intended for external access.“Since these internal activities often handle authentication tokens and session data, exploitation could give an attacker access to a user’s therapy records,” Oversecured research says. Other apps were found storing sensitive information locally in ways that any app on the phone could read. This could expose CBT session notes, mood scores, and personal journal entries. Researchers also found unprotected configuration data, such as backend server addresses, and the use of weak random number generators for security keys.Many of the apps also lack basic protections like root detection, the research found. This means that on a rooted phone, other apps could freely access stored health data.

Limited updates raise concerns

In its research, Oversecured also noted that most of these apps still had medium-level problems that weaken overall security. Only four of the 10 apps had been updated recently, while others had not seen updates since late 2025 or even 2024.The scans were carried out in late January 2026, and researchers said they could not confirm whether the issues have since been fixed.

Source link

Visited 1 times, 1 visit(s) today

Related Article

The AI apps are coming for your PC

Hi, friends! Welcome to Installer No. 124, your guide to the best and Verge-iest stuff in the world. (If you’re new here, welcome, send me your Coachella fits, and also you can read all the old editions at the Installer homepage.) This week, I’ve been reading about restaurant bread and GLP-1s and Lenny Rachitsky and

4 Of The Best iPhone Apps You May Have Missed In 2025

Tada Images/Shutterstock The iPhone has been a mainstay in my daily tech life for over eight years now. During that time, I’ve come to realize that it’s not the latest chip or camera sensors that define its utility for me — it’s the apps created by thousands

I shot over 200 photos with Galaxy S26 Ultra vs. Galaxy S26 — here’s the winner

If you’re thinking about upgrading your phone and considering Samsung’s new flagship lineup, you might be wondering which one to get: the Galaxy S26 or Galaxy S26 Ultra. From a price perspective, there’s a common assumption that the more expensive phone is going to deliver better camera performance — but you might be surprised. That’s

Morgantown man creates ‘DrunkProof’ app

MORGANTOWN, W.Va. (WBOY) — Whether you’ve ever sent or received a drunk text or phone call, the typical repercussions are usually embarrassing at best, but one Morgantown man has created an app to help avoid those situations entirely. “DrunkProof” is an app that locks selected apps and contacts until the morning after to avoid any

WV DMV Mobile ID tops 35,500 users as program keeps growing

CHARLESTON — The West Virginia Division of Motor Vehicles says enrollment in its Mobile ID program continues to climb, with more than 35,500 West Virginians — 35,537 as of this week — now using a digital version of their driver’s license on their phones. The DMV said West Virginia is ahead of the curve nationally.

Best Casino Apps & Mobile Casinos: Expert April 2026 Rankings

April 17, 2026, 7:09 p.m. ET The best casino apps put real-money slots, blackjack, roulette, live dealer tables and more right in your pocket. Available on the Apple App Store and Google Play Store, the best casino apps from licensed U.S. operators pair smooth gameplay with fast withdrawals and generous welcome bonuses. The best casino

India drops plan to force Apple to preinstall state owned app on iPhones

Reuters reports that the Indian government has given up on its plan to mandate that Apple and other smartphone makers pre-install a state-owned “security” app. Here are the details. India backs down on controversial plan Late last year, the Indian government instructed Apple, Samsung, and other smartphone manufacturers to pre-install Sanchar Saathi, an undeletable state-run

Apple now supports multiple AI chatbot apps on CarPlay

Apple CarPlay Starting with iOS 26.4, Apple now supports AI chatbot apps on the iPhone via CarPlay.ChatGPT was the first to add support shortly after the iOS 26.4 release. Now a second AI chatbot has joined: Perplexity. Zac Hall for 9to5Mac:‎ Similar to ChatGPT for CarPlay, Perplexity’s CarPlay app is designed about voice chat. Unlike

NBA Playoffs Prediction Market Apps: Get Best Offers for Trades This Weekend

Photo Credit: Craig Dudek Photo Credit: Craig Dudek This article contains references to products from our advertisers and/or partners, and… Photo Credit: Craig Dudek Photo Credit: Craig Dudek This article contains references to products from our advertisers and/or partners, and we may receive compensation when you click on links to products and services Take advantage

Smartphone Prices Are Still Climbing. Here Are 3 Ways to Get Around That

In today’s market, your smartphone might be the only thing in your pocket that’s gaining value. While we’re used to electronics getting cheaper as they age, a combination of RAM shortages, shifting tariffs and inflation is forcing months-old smartphones to get unprecedented midlife price hikes of up to $200. Meanwhile, new phones that usually get major

Generational launches cell-level EV battery voltage testing

Generational, the UK-based innovator in electric vehicle (EV) battery condition diagnostics, has launched cell-level voltage testing for EV batteries, giving non-technical staff at automotive retailers deeper visibility into battery performance and enabling them to identify potential issues before they impact vehicle value, drivability or customer satisfaction. The new capability expands Generational’s battery diagnostics platform, allowing

UK-based sports technology company Kabuni appoints World Cup-winning cricketer Shane Watson as Super Coach

LONDON, April 17, 2026 /PRNewswire/ — Kabuni, a UK–based sports technology company focused on cricket training and player development, today announced the appointment of former Australian international cricketer Shane Watson as its first Super Coach. Kabuni CEO and Founder Nimesh Patel and former Australia international cricketer Shane Watson confirm Watson’s appointment as the training platform’s

Global EV Fleet Management Market: Growth, Trends, and Forecast

EV fleet management market set to surge with smart charging, analytics, and electrification driving efficiency and sustainability. The global EV fleet management market is experiencing rapid expansion, reflecting the broader transformation of the transportation and logistics sectors toward electrification. In 2025, the market was valued at USD 9.28 billion, and it is projected to grow

This US EV Market Share Chart Is Quite Lame

Support CleanTechnica’s work through a Substack subscription or on Stripe. Cox Automotive collects the most extensive data on US EV sales, through its long famed and respected arm Kelley Blue Book. In the opening paragraph of its latest report on the market, the company provided a slight silver lining: “At 216,399, EV sales in Q1

I found the apps slowing down my PC – how to kill the biggest memory hogs

Kyle Kucharski/ZDNET Follow ZDNET: Add us as a preferred source on Google. ZDNET’s key takeaways Dozens of processes run in the background on your PC, and each takes a bit of memory. Most are necessary and helpful, but some can be disabled to optimize performance.  Checking to see which ones load automatically is a good place to

Android Phones Shown to Have a Major Biometric Security Weakness

Summary created by Smart Answers AI In summary: Tech Advisor reports that 64% of Android phones tested since 2022 have facial recognition systems easily fooled by simple 2D photos. Major brands including Samsung flagships, Oppo, and Motorola failed security tests, while Google Pixel and Apple iPhone models passed using more secure technology. This vulnerability exposes

NJ Bill Banning Apps That Hoard Restaurant Reservations Could Become Law

Is it fair that apps can snap up tables at the hottest restaurants in New Jersey and resell them—sometimes to the highest bidder, and sometimes not at all? Some state legislators don’t think so. A bill banning such third-party businesses, which passed the state Senate and Assembly in March, is currently on Governor Mikie Sherrill’s

0
Would love your thoughts, please comment.x
()
x