Chinese, Russian SDKs Raise Military App Privacy Risks

News Room

The biggest privacy risk on smartphones may not be the apps themselves, but the third-party code quietly running inside them.

Researchers from Purdue University, West Point and Florida International University found that several commercial Android apps marketed to U.S. military personnel include third-party software development kits (SDKs) from companies based in China and Russia.

According to a Wired report, the researchers found no evidence of current data exfiltration. They, however, stress that SDKs can receive updates over time, suggesting that code that appears harmless today could potentially change after development.

Beyond the military, the underlying lessons also affect enterprises and individual app users by highlighting a gap they might be unaware of. Software reviews often focus on the company that publishes an application, while the third-party code embedded in it goes unnoticed.

What the researchers found

The report found that more than one in eight consumer Android apps marketed to U.S. military personnel contained third-party software from companies based in China or Russia. The finding came after an analysis of more than 220 apps.

Such third-party software powers common functions such as maps, analytics, cloud services, and notifications, and is widely used throughout the mobile app industry.

While the researchers found no evidence that the observed SDKs were being used to spy on military personnel or exfiltrate sensitive information, they expressed concern that users may be unaware of the potential risks posed by those components.

One finding stood out. Researchers found that 40% of the apps collected or shared more user data than their developers disclosed. That suggests privacy labels should be treated as a starting point and not a definitive record of an application’s data practices.

What does this mean for enterprises, developers, and end-users?

While the research focused on apps used by military personnel, its implications extend well beyond the defense sector. At its core, the study highlights two challenges that affect virtually every organization today: limited visibility into software supply chains and an overreliance on developer privacy disclosures.

The study also exposes a security blind spot. An organization may thoroughly vet an application’s developer, only for that app to rely on third-party SDKs maintained by vendors that fall outside the

organization’s own security or compliance standards. Those dependencies often receive less scrutiny, even though they run with the same permissions as the host application.

As organizations face growing concern over software supply chain attacks, understanding who built an application is no longer enough. Security teams also need visibility into the external code shipped with it, how that code is maintained, and how it changes over time.

The lesson extends beyond enterprises. For individuals, an app’s presence on an official app store, its reputation, or the credibility of its developer should not automatically be taken as proof that every component inside it is equally trustworthy.

For developers, while relying on third-party SDKs is now a standard part of modern software development, that convenience comes with a responsibility to vet and continuously reassess these vendors. A trusted dependency can become a security or compliance risk if its ownership, code or behavior changes after deployment.

Other News: Chris Fall’s abrupt departure after just three months as head of the Trump administration’s AI safety agency raises new questions about the future of U.S. AI oversight as Washington reshapes its approach to regulating frontier AI.

Read the full article here

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *