Pre-installed Android apps pose huge security and privacy risks, study says

Android
Image credit: Android

It was only a month ago that pre-installed malware was discovered on Android-based Alcatel smartphones, and other such security flaws are no stranger to apps found on Google’s own Play Store.

But a recent study analyzing pre-installed Android software has found that many vendors that provide their own version of the open-source operating system abuse the platform in order to release products with integrated data collecting services.

The analysis was conducted by IMDEA Networks Institute, Universidad Carlos II de Madrid, Stony Brooks University and ICSI, and covered more than 200 device manufacturers, 1,700 devices, and 82,000 pre-installed apps.

This study concluded that, whether through deliberate misuse or poor practices, companies creating their own Android-based firmware for smartphones had a tendency to enable third-party access to user data in its software and, furthermore, hide such activity from the user.

“This situation has become a peril to users’ privacy and even security”, the paper claims, “due to an abuse of privilege, such as in the case of pre-installed malware, or as a result of poor software engineering practices that introduce vulnerabilities and dangerous backdoors.”

The analysis found that it wasn’t just the smartphone manufacturer responsible for such transgressions, but a “myriad of actors” ranging from software developers to advertisers and that these parties are potentially involved in secret partnerships.

“Users’ activities, personal data, and habits may be constantly monitored by stakeholders that many users may have never heard of, let alone consented to collect their data,” the study finds.

As for solutions to the lack of transparency that these researchers uncovered, they suggest the introduction of an objective “globally-trusted” regulatory body that would sign software certificates rather than the vendors themselves, as well as clear and public documentation of pre-installed apps, their purpose, and the entity responsible for them. 

Google has responded to TechCrunch on the issue, claiming that the report’s methodology “is unable to differentiate pre-installed system software [...] from malicious software that has accessed the device at a later time”, and that the company works closely with, and provides tools for, its partners in order to protect against software that violates its policies.

TOPICS
Harry Domanski
Harry is an Australian Journalist for TechRadar with an ear to the ground for future tech, and the other in front of a vintage amplifier. He likes stories told in charming ways, and content consumed through massive screens. He also likes to get his hands dirty with the ethics of the tech.
Latest in Websites & Apps
A mobile phone showing the Signal logo in front of a screen showing the app
Signalgate explained: what is Signal, and how secure is the messaging app?
Quordle on a smartphone held in a hand
Quordle hints and answers for Friday, March 28 (game #1159)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Friday, March 28 (game #390)
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
Quordle on a smartphone held in a hand
Quordle hints and answers for Thursday, March 27 (game #1158)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Thursday, March 27 (game #389)
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does