The official Beijing Winter Olympics athlete app reportedly has some mega security flaws

China's flag overlays laptop screen
(Image credit: Shutterstock)

Participants of the upcoming Beijing Winter Olympics are required to use a mobile app marred with security flaws, researchers have claimed.

The My 2022 mobile app for iOS and Android devices is required by all participants of the upcoming games (including athletes, visitors, journalists, and others) for a number of functions, including chat messaging, translation, transport, competition information, as well as health data.

All users must share their passport details and their travel plans with the app, and add personal health information, such as body temperature, any respiratory difficulties, or any medications used, two weeks before arriving in the country, and make sure they keep using it while they’re in China.

App flaws

However the app can apparently be tricked into visiting a malicious website, according to researchers from CitizenLab. The team explained how the app fails to validate SSL certificates used to authenticate a website’s identity and make sure the connection is secure. Visitors could end up sharing login information with a fake website, or even downloading malware.

The chat service is also flawed, the researchers added, failing to properly encrypt metadata transferred through the service, which means that certain metadata going through public Wi-Fi could be intercepted. That metadata includes the chat participants’ names, and account identifiers. 

Unsurprising findings 

The researchers found these flaws primarily in the iOS version, as they weren’t able to create an account on the Android version. However, they claim to have found similar vulnerabilities in publicly available features. 

They’re also saying that these vulnerabilities are probably not deliberate, but rather a consequence of China’s “lax enforcement of cybersecurity standards”. Finding the flaws wasn’t that big of a surprise for them. 

“While we found glaring and easily discoverable security issues with the way that My 2022 performs encryption, we have also observed similar issues in Chinese-developed Zoom, as well as the most popular Chinese web browsers,” the report said.

The researchers also said they found a list of some 2,400 politically sensitive keywords in the Android version. Although the list is inactive at the moment, it could be used to censor communications through the app.

Most of the terms were in simplified Chinese, with others being in Tibetan, Uyghur, traditional Chinese and English. 

  • You might also want to check out our list of the best firewalls right now

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Photograph of a woman in workout gear sat on a yoga mat whilst using a smartphone to check out a fitness app
Work up a sweat without exposing your personal data – here's how to safely use fitness apps
DeepSeek
Experts warn DeepSeek is 11 times more dangerous than other AI chatbots
Young parents and their kids sitting on the floor on New Year's eve and using wireless technology.
Beware, popular Christmas apps are bad for your privacy
Image of three women checking a fitness tracker and app
Is 10,000 steps a day worth your personal data? How 80% of fitness apps are selling your privacy
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection