Updated
Updated · gadgetreview.com · Jul 20
Study Finds 1 in 8 U.S. Military Apps Carry Adversary Code
Updated
Updated · gadgetreview.com · Jul 20

Study Finds 1 in 8 U.S. Military Apps Carry Adversary Code

3 articles · Updated · gadgetreview.com · Jul 20

Summary

  • More than one in eight apps marketed to U.S. troops contained code from firms in China, Russia or other Pentagon-designated adversary nations, according to a study of 220-plus apps by Purdue, West Point and Florida International University.
  • Sixty-four percent of the apps used third-party SDKs for ads, analytics or notifications, creating hidden supply-chain paths; 12 apps carried Huawei HMS Core, including some built for state National Guard organizations.
  • Researchers found 40% of the apps collected or shared more data than their app-store privacy labels disclosed, and warned remotely updated SDKs could turn dormant access into active collection even when developers do not realize the code is present.
  • CENTCOM already told Senator Ron Wyden that adversaries have exploited commercial location data to target U.S. personnel near Iran and the Strait of Hormuz, underscoring how consumer app data can expose troop movements and routines.
  • Among 103 military-affiliated respondents, more than 83% used at least one app with uncomfortable data practices, while in-phone warnings about foreign code drew the strongest support as a fix; the Pentagon declined to comment.

Insights

As adversaries hunt US troops using app data, why are military phones still not secured against basic tracking?
Is banning foreign code a real fix when data brokers can sell US military secrets for just pennies?
When spyware can be smuggled into apps, how can developers or users ever ensure their software is truly safe?

National Security at Risk: The Real-World Impact of Foreign Code and Data Exploitation in U.S. Military Applications

Overview

This report highlights the immediate and growing threat to U.S. national security from foreign-linked code embedded in popular apps used by military personnel. It explains how extensive commercial data practices, such as those in the adtech industry, inadvertently enable adversarial surveillance and targeting. The presence of hidden foreign ties in applications, especially VPNs traced back to China, puts users’ privacy and national security at risk, often without their knowledge. These vulnerabilities create real-world exploitation opportunities, leading to potential operational disruption and underscoring the urgent need for stronger safeguards and oversight in military digital environments.

...