The bottom line: More than 2.4 billion installations of free Android VPN apps with fundamental security flaws such as uncontrolled traffic leaks and missing encryption.
Researchers analyzed 281 popular free VPN apps from the Google Play Store and identified fundamental security deficiencies: 29 apps allow user traffic to leak unprotected, many transmit data unencrypted.
A systematic analysis of the 281 most-used free VPN applications in the Google Play Store has revealed significant protection gaps. The affected apps have been installed a combined total of more than 2.4 billion times, illustrating the extent of security risks for end users.
The identified problems are not highly complex attack vectors, but rather fundamental shortcomings in the implementation of VPN core functions. 29 of the analyzed apps allow user traffic to be routed outside the VPN tunnel — a critical failure scenario that completely fails to fulfill the central protective mandate of a VPN application.
For CISOs, this means that free VPN apps on company-owned or BYOD devices represent a significant data protection and compliance risk. When employees use these apps, business-critical information and identity data can be transmitted in plaintext despite allegedly having VPN protection. A strict policy for approving network security tools and their regular review are necessary.
Source: thehackernews.com · Published 10 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.