The bottom line: 29 of 281 free Android VPN apps examined leak user data unencrypted outside the VPN tunnel – a fundamental security failure affecting over 2.4 billion installations.
An analysis of 281 popular free VPN apps from the Google Play Store reveals that many apps fail to deliver their core function: they do not reliably protect user data. The affected apps have already been installed over 2.4 billion times.
Security researchers examined 281 of the most popular free VPN applications for Android using a new testing methodology. The results are alarming: many apps fail to meet the most basic requirements that users expect from a VPN solution – namely, protection of their internet connection and confidentiality of their data.
The identified problems are not the result of sophisticated attack techniques, but rather stem from fundamental implementation flaws. 29 of the tested apps allow user data to be transmitted outside the VPN tunnel – a leak that undermines the entire security architecture of a VPN application. Such traffic leaks are often undetectable to end users and erode confidence in the encryption of the connection.
The total download count of apps with at least one security issue exceeds 2.4 billion installations. This means that a substantial number of users are potentially using unprotected or inadequately encrypted traffic without realizing it. For CISOs, this is relevant because widely distributed free VPN apps are frequently used by employees on private networks or for business purposes, which poses security risks to corporate infrastructure as well.
Source: thehackernews.com · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.