Trump and Biden official election apps vulnerable to hackers

US election 2020
(Image credit: Shutterstock.com / chrisdorney)

The official 2020 election apps of both President Trump and Joe Biden feature significant security issues, researchers have claimed.

With the US Presidential election now just a few days away, doubts have been raised over the security of the official apps used by both candidates by researchers at security firm Promon.

The company found that both the Trump and Biden apps are vulnerable to StrandHogg, a well-known and critical Android vulnerability that allows hackers to easily hijack apps and overlay fake screens which can depict anything the attacker wants, including screens that ask the user to hand over sensitive information, such as usernames and passwords.

Election apps hacked

The news comes despite President Trump recently declaring at a campaign rally that, "Nobody gets hacked. To get hacked you need somebody with 197 IQ and he needs about 15% of your password”.

Promon was able to use StrandHogg to overlay fake screens - one on Trump’s app, calling on users to donate to the Biden campaign, and another on official the Biden app, showing the Democratic candidate in a MAGA hat, urging users to vote for Trump. 

“The President’s statement sadly reflects a widely believed sentiment that secure passwords will protect you from hackers and that hacking, in general, doesn’t affect the average citizen," noted Tom Lysemose Hansen, CTO at Promon.

"Sadly, this isn’t the case. Absolutely nothing is “unhackable” and even the most secure, high profile accounts are vulnerable should the user fall victim to a phishing attack which seeks usernames and passwords."

The report comes shortly after the official Trump re-election campaign in the state of Wisconsin said it had lost $2.3 million to hackers who carried out a phishing attack.

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring