zimperium.com Widespread Privacy Risks in Mobile VPN Apps Identified
Article Content
- •Zimperium found significant flaws in 800 free mobile VPN apps, affecting user privacy.
- •Proton's survey revealed that 85% of US VPNs contain trackers, with 25% tracking location.
- •VPN apps can pose enterprise risks, especially for organizations with BYOD policies.
A recent analysis of over 800 free mobile VPN apps revealed significant security flaws, with many apps leaking personal data and requesting excessive permissions. Zimperium zLabs found that these vulnerabilities pose risks not only to individual users but also to organizations with BYOD policies, as these apps can compromise sensitive business data. Concurrently, a survey by Proton indicated that 85% of mobile VPNs in the US contain trackers, with a quarter actively tracking users' locations. The findings raise serious concerns about the integrity of VPN services, particularly those owned by companies in high-risk jurisdictions, such as China. Despite the widespread use of VPNs for privacy protection, users may be unknowingly exposing themselves to greater risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2014-0160 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which VPN apps are affected?
What should organizations do?
Are these vulnerabilities actively exploited?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…