Popular Android apps are leaking user data online

Data leak
(Image credit: Shutterstock/dalebor)

Over a dozen top Android apps listed on the Google Play Store were found to be leaking user data, according to a cybersecurity investigation.

Analyzing the configuration of popular Android apps, security researchers at CyberNews found that 14 top Android apps with over 140 million collective installs are leaking sensitive user data due to improper access controls on their Firebase real-time database.

Mobile app developers use Firebase real-time databases to store user records, financial information, and other kinds of sensitive data. Unfortunately, real-time databases are often managed by developers with no security training, which makes them an easy target for malicious actors,” notes CyberNews.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

According to the researchers, the misconfiguration enabled them to access the real-time databases and the information it houses about the users without being prompted for any kind of authentication.

Fire in the hole

CyberNews claims to have reached out to the developers of all fourteen apps, five of which have since secured access to their Firebase databases. However, since a majority of the developers didn’t respond to the researchers, CyberNews reached out to Google to solicit their help in getting the developers to fortify their databases.

“Unfortunately, Google has ignored our queries, and we have not heard from them since,” claims CyberNews, adding that the nine unsecured apps continue to leak data of their combined user base of over 30 million individuals.

“If you’re an app developer, always make sure to follow the official Firebase real-time database security guidelines provided by Google,” suggests CyberNews researcher Martynas Vareikis.

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Stalkerware
New spyware found to be snooping on thousands of Android and iOS users
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
This widely-used instant loan app leaks nearly 30 million files of user data
Data Breach
Thousands of widely-used public workspaces are leaking data
Businessman holding a magnifier and searching for a hacker within a business team.
Top Mexican fintech firm leaks details on 1.6 million customers
Latest in Security
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Microsoft
Microsoft names cybercriminals who created explicit deepfakes
A laptop with a red screen with a white skull on it with the message: &quot;RANSOMWARE. All your files are encrypted.&quot;
More reports claim 2024 was the worst year for ransomware attacks yet
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
Latest in News
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Pulchra Fellini in Zenless Zone Zero.
Zenless Zone Zero Version 1.6 will finally let you play as a furry gunslinger
Two hands holding the Tecno Spark Slim phone
The world’s thinnest phone was just revealed, but a new iPhone 17 Air leak suggests it could be even slimmer
Polish space agency says it was hit by a cyberattack
The new limited edition Ray-Ban Meta smart glasses show a translucent design.
Ray-Ban and Meta just teased new limited-edition smart glasses – but they'll be in frustratingly short supply