Security flaws found in top free VPN Android apps

VPN
Image Credit: Pixabay (Image credit: Pixabay)

Android users looking for free VPN apps on the Google Play Store may want to think twice after research from Top10VPN revealed that one in five of the top 150 free VPN apps could be a potential source of malware, while a quarter of the apps contain privacy-compromising bugs such as DNS leaks.

The company's Head of Research, Simon Migliano, made the discovery, and found that these Android VPN apps have already been installed 260 million times according to Google.

Top10VPN has organized and published its findings in the form of a risk index with the aim of helping Android users understand the privacy risks they are exposing themselves to when installing a free VPN.

Of the top 150 free VPNs, 27 apps were flagged as a potential source of malware after being tested using the utility VirusTotal.

DNS leak

Additionally, 25% of the top 150 free VPNs on the Google Play Store were affected by a DNS leak security issue which Migliano explained further in a blog post, saying:  “This security flaw occurs when a VPN fails to force DNS requests through its encrypted tunnel to its own DNS servers and instead permits the DNS requests to be made directly to the default ISP DNS servers.

“Even though the rest of a user’s traffic is concealed, such a leak exposes a user’s browsing history to their ISP and any third-party DNS server operator that it may use.”

Top10VPN also discovered that some free VPNs were asking users for highly intrusive permissions, with 25% of apps asking to access a user's location, 38% tried to access device status information and 57% included code to retrieve a user's last known location.

While a free VPN may sound enticing at first, there will always be some kind of tradeoff, and we highly recommend researching any VPN extensively before installing it on your devices.

Via Bleeping Computer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in VPN Privacy & Security
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Tor
What is Onion over VPN?
Latest in News
Core Time 2 + iPhone 15 blue
Pebble is taking the fight to the Apple Watch – as its founder calls for action
The Google Pixel 9a
The Google Pixel 9a’s AI has a RAM problem
Xbox Wireless Controller
Microsoft is adding a powerful new feature for using Xbox controllers with Windows 11
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Oracle
Oracle unveils multi-billion dollar investment in UK cloud and AI
Taco Bell AI Drive-Thru
AI is taking over your favorite fast food restaurants as Taco Bell, Pizza Hut, and KFC team up with Nvidia - 500 locations by the end of 2025