Insecure Mobile VPNs: The Hidden Danger
ID: 3a91955d-dbfb-5e5f-9020-339391acb27f
STIX ID: report--3a91955d-dbfb-5e5f-9020-339391acb27f
Feed Name: Zimperium Blog
Zimperium zLabs analyzed roughly 800 free Android and iOS VPN apps and found pervasive security and privacy weaknesses — including outdated vulnerable libraries (notably some apps still using OpenSSL vulnerable to Heartbleed), certificate-validation flaws enabling man-in-the-middle attacks, missing or misleading privacy manifests and labels, excessive or unexpected permissions (e.g., AUTHENTICATE_ACCOUNTS, READ_LOGS, LOCATION_ALWAYS), private entitlements on iOS, exported components and risky APIs that can lead to data leakage, privilege escalation, or remote code execution — posing significant consumer and enterprise BYOD risk and recommending mobile app vetting and developer remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
