Over 1,000 Android apps are harvesting your data without permission
A new research study revealed that more than 1,000 Android apps available in Google Play Store violated permissions to steal private data such as messages, call logs, photos and more.
Researchers from UC Berkeleyโs International Computer Science Institute (ICSI), which produced the research, tested 88,000 apps from the U.S.ย Googleย Play Store, and found that 1,325 apps collected information regarding geolocation data and phone identifiers.
Related- 10 Of The Best Free Android Apps
The study published on the Federal Trade Commission (FTC) website cited 153 apps, includingย Samsungย Health, Samsungโs Browser, Shutterfly and Disneyโs Hong Kong Disneyland park app that collected data without explicit permissions.
“Modern smartphone platforms implement permission-basedย models to protect access to sensitive data and system resources. However, apps can circumvent the permission modelย and gain access to protected data without user consent by using both covert and side channels,” wrote the researchers in an extensive report.
“Side channels present inย the implementation of the permission system allow apps toย access protected data and system resources without permission; whereas covert channels enable communication betweenย two colluding apps so that one app can share its permission-protected data with another app lacking those permissions.ย Both pose threats to userย privacy.”
For instance, the researchers found Shutterfly – the photo-sharing website used for editing photos โ to be collecting GPS data from mobile phones and sending it to its own servers, irrespective of whether users have allowed or declined the app permission to access location data.
“Like many photo services, Shutterfly uses this data to enhance the user experience with features such as categorization and personalized product suggestions, all in accordance with Shutterfly’s privacy policy as well as the Android developer agreement,” the company said in a statement responding to the study clarifying that it only collects GPS data on those that give it permission.
In the case of Hong Kong Disneyland, it was found the app used SD card as a covert channel to store phone’ IMEI information. Although 13 apps were found to be exploiting this covert channel to get the IMEI information, these apps were installed more than 17 million times.
“The number of potential users impacted by these findings is in the hundreds of millions. These deceptive practices allow developers to access users’ private data without consent, undermining user privacy and giving rise to both legal and ethical concern,” the researchers wrote.
โData protection legislation around the worldโincluding the General Data Protection Regulation (GDPR) in Europe, the California Consumer Privacy Act (CCPA) and consumer protection laws, such as the Federal Trade Commission Actโenforce transparency on the data collection, processing, and sharing practices of mobile applications.โ
The researchers who had reported their findings to Google in September last year say that some of them may be fixed in the upcoming Android Q operating system scheduled to release this year. This means that several older smartphone usersย who donโt receive the Android Q updates will continue to face the problem leaving their handsets vulnerable.
Related- Microsoft Is Injecting Ads To Install Its Other Apps In Android
โBy uncovering these practices and making our data public, we hope to provide sufficient data and tools for regulators to bring enforcement actions, industry to identify and fix problems before releasing apps, and allow consumers to make informed decisions about the apps that they use,โ the researchers said.
The researchers suggest that Google should consider these privacy issues as serious security vulnerabilities and need to upgrade the way permissions function.
Also Read- Best Free Antivirus For Android Smartphones