Android mental health apps with 14.7M installs filled with security flaws

Android mental health apps with 14.7M installs filled with security flaws

Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users’ sensitive medical information.

In one of the apps, security researchers discovered more than 85 medium- and high-severity vulnerabilities that could be exploited to compromise users’ therapy data and privacy.

Some of the products are AI companions designed to help people suffering from clinical depression, multiple forms of anxiety, panic attacks, stress, and bipolar disorder.

Wiz

At least six of the ten analyzed apps state that user conversations or chats remain private, or are encrypted securely on the vendor’s servers.

“Mental health data carries unique risks. On the dark web, therapy records sell for $1,000 or more per record, far more than credit card numbers,” says Sergey Toshin, founder of mobile security company Oversecured.

Over 1,500 security issues found

Oversecured scanned ten mobile apps advertised as tools that can help with various mental health problems, and uncovered a total of 1,575 security vulnerabilities (54 rated high-severity, 538 medium-severity, and 983 low-severity).












  App Type Installs High Medium Low Total Scan date
01 Mood & habit tracker 10M+ 1 147 189 337 01/23/2026
02 AI therapy chatbot 1M+ 23 63 169 255 01/22/2026
03 AI emotional health platform 1M+ 13 124 78 215 01/23/2026
04 Health & symptom tracker 500k+ 7 31 173 211 01/22/2026
05 Depression management tool 100k+ 66 91 157 01/23/2026
06 CBT-based anxiety app 500k+ 3 45 62 110 01/22/2026
07 Online therapy & support community 1M+ 7 20 71 98 01/23/2026
08 Anxiety & phobia self-help 50k+ 15 54 69 01/22/2026
09 Military stress management 50k+ 12 50 62 01/22/2026
10 AI CBT chatbot 500k+ 15 46 61 01/23/2026

Although none of the discovered issues are critical, many can be leveraged to intercept login credentials, spoof notifications, HTML injection, or to locate the user.

The researchers used the Oversecured scanner to check the APK files of the ten mental health applications for known vulnerability patterns in dozens of categories.

In a report shared with BleepingComputer, the researchers say that some of the verified apps “parse user-supplied URIs without adequate validation.”

One therapy app with more than one million downloads uses Intent.parseUri() on an externally controlled string and launches the resulting messaging object (intent) without validating the target component.

This allows an attacker to force the app to open any internal activity, even if it is not intended for external access.

“Since these internal activities often handle authentication tokens and session data, exploitation could give an attacker access to a user’s therapy records,” Oversecured explains.

Another issue is storing data locally in a way that gives read access to any app on the device. Depending on the saved information, this could expose therapy details, such as therapy entries, Cognitive Behavioral Therapy (CBT) session notes, and various scores.

Oversecured states that they also discovered plaintext configuration data, including backend API endpoints and a hardcoded Firebase database URL, within the APK resources.

Furthermore, some of the vulnerable apps use the cryptographically insecure java.util.Random class for generating session tokens or encryption keys.

According to the researchers, “most of the 10 apps lack any form of root detection.” On a rooted (jailbroken) device, any app with root privileges has access to all health data stored locally.

Oversecured says that six of the ten analyzed apps “had zero high-severity findings, but still carried medium-severity issues that weaken their overall security posture.”

“These apps collect and store some of the most sensitive personal data in mobile: therapy session transcripts, mood logs, medication schedules, self-harm indicators, and in some cases, information protected under HIPAA,” the researchers note.

From BleepingComputer’s observations the collective download count for the apps scanned by Oversecured is more than 14.7 million, and only four received an update as recently as this month. For the rest, the date of the latest update was as recent as November 2025 or even September 2024.

Oversecured’s scans occurred between January 22 and 23 and targeted the latest app versions available at the time. The researchers cannot confirm if any of the uncovered vulnerabilities have been addressed. 

BleepingComputer has refrained from the sharing the names of the impacted apps as the vulnerabilities are still being disclosed by Oversecured.

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

Source link

Visited 1 times, 1 visit(s) today

Related Article

iOS 26.4 makes two app updates that bring back iOS 18 designs

iOS 26.4 beta 2 arrived today for developers, with two app changes that reverse iOS 26 search designs to be more like iOS 18. Search design has reversed to iOS 18 behavior in some iOS 26.4 apps Last week when iOS 26.4 beta 1 debuted, it came with some odd design quirks in the App

ET logo

Karnataka weighs mobile ban for students, says Dy CM; schools urge caution

Bengaluru: Deputy Chief Minister DK Shivakumar on Monday said the government was actively discussing a ban on use of mobile phones by school children amid growing concerns over the impact of excessive screen time on them. The government has been under pressure from parents to act decisively, the Dy CM told the media in Bengaluru.

I ditched Duolingo for this language app, and it was a total reality check

Duolingo met with significant backlash in April 2025 when CEO Louis von Ahn declared that he would only hire if that job couldn’t be done with AI. The memo from which this controversial message came also contained inflammatory statements about how the app would “take occasional small hits on quality” and that the company would

WhatsApp: Group Chats are Getting This Long-Overdue Feature

Summary created by Smart Answers AI In summary: Tech Advisor reports that WhatsApp is rolling out a long-awaited feature allowing users to share up to 100 recent messages with new group members. The manual feature offers flexible options to share 25, 50, 75, or 100 messages while maintaining end-to-end encryption for security. Group admins can

Wispr Flow launches an Android app for AI-powered dictation

AI-powered dictation startup Wispr Flow has launched its Android app today. The company released its app for Mac and Windows first, then launched on iOS in June 2025. On iOS, users could use Wispr Flow through a dedicated keyboard. On Android, the interface is a bit different, as you can access the dictionary through a

Microdramas Overtake Streamers on Mobile Engagement, Says Omdia

Microdramas are rapidly emerging as one of the fastest-scaling formats in online video. Omdia analysis of mobile usage data shows that in the US users now spend more time per day watching microdramas on mobile apps than they do watching Netflix, Disney+ or Amazon Prime Video on mobile devices. This press release features multimedia. View

Digital plumbing: The infrastructure behind dating apps

As we approach Valentine’s Day, many people are searching for love, or just companionship, and many of them are using dating apps to help in that search. Hundreds of millions of people use dating apps worldwide, and the sector generates billions of dollars in annual revenue. Tinder remains one of the dominant dating apps. There

Missouri Sports Betting Apps: Download the Best Missouri Betting Apps

Download the best Missouri sports betting apps at launch today. Learn more about app features, ratings and more for Missouri sports betting apps. MLB Draft Kit Prepare for your baseball season with RotoWire’s MLB Draft Kit including rankings, auction value support, and mock draft simulator. With sports betting now legal in the Show-Me State, Missouri

5 iPhone Apps That Let You Control Your Car Without A Key

RSplaneta/Shutterstock The world of car technology is always advancing, now giving you the ability to store your car keys on your iPhone or on your Android smartwatch. This can usually be done through your vehicle’s associated app, if one is available for your model. These apps allow

Building ClawBeat With AI: My First Production App

ClawBeat.co is the destination for all your news, research papers, videos, and GitHub repos about OpenClaw. Credit: Ken Yeung They say that “the first step is always the hardest.” It’s the thought that tends to surface whenever I begin something new—photography, writing, or a skill I’m not sure I’m ready to learn. The hesitation is

POP! Slots, myVEGAS, myKONAMI and MGM

If you’re looking for the best social casino games, Playstudios, an internationally-renowned technology and gaming company, offers plenty of great options. Below, I’ll highlight some of the brand’s top free games, including POP! Slots, myVEGAS slots, myKONAMI Slots, and MGM Slots Live. Best social casino games at POP! Slots, myVEGAS Slots, myKONAMI Slots & MGM

7 Apps That Can Help You Sleep Better While Traveling

Yacobchuk/Getty Images Travel is wonderful, but it doesn’t come without problems. Staring at a hotel ceiling, waiting for a sleepy feeling that never arrives, is one. The hum of your room may be off just enough to irritate, or the street noise outside may be different from

Move over, Apple: Meet the alternative app stores available in the EU and elsewhere

People in the European Union are now allowed to access alternative app stores thanks to the Digital Markets Act (DMA), a regulation designed to foster increased competition in the app ecosystem. Like Apple’s App Store, alternative app marketplaces on allow for easy access to a wider world of apps on Apple devices, but instead of

A Gurugram horror story| India News

A 19-year-old student’s life turned into a nightmare in Gurugram after a relationship that began on a mobile app led to a horrific case of brutality. The woman, originally from Tripura, was pursuing a BSc in biotechnology and living in a PG accommodation in Sector 69 when she met the accused, who is from Delhi’s

Pay for your Android apps—here are 6 I’m glad I bought

Most of us don’t want to pay for software, which is how we’ve ended up with intrusive ads and free-to-play addiction traps. But for just a few bucks, your mobile experience can be much, much better. I pay for my Android apps, and here are some I can easily recommend as being worth their price.

0
Would love your thoughts, please comment.x
()
x