Study Finds 281 Free Android VPN Apps Leak Traffic, Expose Unencrypted Data and Track Users
What Happened — Researchers evaluated 281 of the most‑downloaded free VPN apps on Google Play and discovered that many fail at the core promise of a VPN. At least 29 apps allowed user traffic to exit the encrypted tunnel, dozens transmitted data over plain HTTP, and a large fraction embedded third‑party analytics SDKs that can track users. The flagged apps collectively have more than 2.4 billion installations.
Why It Matters for Compliance & Audit Readiness
- The issue is a classic data‑in‑transit control gap, directly violating SOC 2 CC6.1 which requires encryption and isolation of sensitive traffic.
- Continuous evidence of VPN configuration compliance can serve as audit‑ready proof that remote‑access controls are effective.
- Verisq’s Control Mapping capability can automatically capture VPN configuration evidence, flag deviations, and provide a defensible audit trail.
Who Is Affected — Consumer mobile users, enterprises that permit BYOD or rely on free VPNs for remote work, and the free‑VPN providers themselves.
Recommended Actions — Review and tighten VPN usage policies, enforce a vetted list of approved VPN solutions, map VPN encryption controls to SOC 2 criteria, and collect continuous configuration evidence to demonstrate compliance. Source: [The Hacker News]
Technical Notes — Testing uncovered traffic leaks via DNS, IPv6, and WebRTC, unencrypted HTTP requests, and hidden tracking SDKs. No specific CVEs were cited; the failures stem from misconfiguration and inadequate implementation. Source: [The Hacker News]