logo

Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military

ID: 711e62d6-f07a-5ae6-89f1-7e14e30f96e1

STIX ID: report--711e62d6-f07a-5ae6-89f1-7e14e30f96e1

Feed Name: TechRepublic Security

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Joseph Ofonagoro

...
...

Researchers from Purdue, West Point, and Florida International University analyzed over 220 Android apps marketed to U.S. military personnel and found that more than one in eight contained third-party SDKs from companies based in China or Russia. While the study found no evidence these SDKs were currently exfiltrating data, it discovered that 40% of apps collected or shared more user data than their developers disclosed and warned that SDKs can be updated post-release, creating a software supply-chain and privacy risk that organizations and users may not fully appreciate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.