This top mobile browser is secretly tracking millions of iOS and Android users

Phone security
(Image credit: Shutterstock)

Cybersecurity researchers have found that a popular mobile web browseris sending records of websites visited by users, even in Incognito mode, to its servers.

UC Browser is developed by UCWeb, which is a subsidiary of Chinese tech giant Alibaba, and is reportedly popular throughout many parts of the world, with over 500 million downloads on the Android Play Store alone.

However, owing to the Indian government’s security concerns over Chinese apps, UC Browser remains banned in the country, where it had been one of the most popular mobile browsers.

TechRadar needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

The issues with UC Browser were initially flagged by security researcher Gabi Cirlig, and have since been verified by two other independent researchers on behalf of Forbes.

In a blog post, Cirlig explains that he was able to observe UC Browser’s irregular behavior by reverse engineering some encrypted data he noticed the browser was piping back to its servers. Thanks to his efforts he was then able to observe that every time he visited a website, the browser would encrypt and transmit the details about the visit. 

Individual tracking

Cirlig has a knack for unearthing unscrupulous activities of Chinese browsers. Last year he found Xiaomi’s browser exhibiting a similar behavior and routing details about visited websites, even when in incognito mode, back to its headquarters. 

In UC Browser’s case, Cirlig noticed that along with the website the browser would also roll in the user’s IP addresses in the transmission to its headquarters.

Even more worryingly, he shared that the browser would assign an ID number to each user, which could be used to track their movements across different websites. 

Although it isn’t clear exactly what Alibaba and its subsidiary are doing with the data, Cirlig told Forbes that “this kind of tracking is done on purpose without any regard for user privacy.”

Interestingly, as of Tuesday morning, the English-language version of UC Browser is no longer listed on the Apple App Store, though it can still be downloaded from Google’s Play Store.

Via Forbes

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Stalkerware
New spyware found to be snooping on thousands of Android and iOS users
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Woman using credit card whilst sitting at a desk with a laptop and mobile phone in view
Best web browser of 2025
Browser
The future of mobile browsers: time for a new model?
Latest in Software & Services
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
a laptop computer
Windows 11 vs ChromeOS for business: Is one better than the other for your needs?
a laptop computer
Windows 11 vs macOS for business: which side are you on?
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
ChatGPT WhatsApp
New survey suggests the vast majority of iPhone and Samsung Galaxy users find AI useless – and to be honest, I’m not surprised
A hunter holds up a Grav Bowfin and smiles
How to catch a Gravid Bowfin in Monster Hunter Wilds
Fujfilm GFX 50R
First Fujifilm GFX100RF images leaked in build-up to expected reveal – here’s what they tell us about the unique premium compact camera
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
Spotify logo on a mobile device
Had Spotify problems recently? It's clamped down on Premium APK 'modded' apps – here's what's happening