Apps targeted at US troops contain Chinese and Russian code
A study of over 220 military-marketed apps revealed that more than one in eight contained software development kits (SDKs) from nations considered adversarial by the Pentagon, including China and Russia. Approximately 64% of the examined apps included third-party code capable of tracking user behavior and location, with 40% collecting or sharing more data than disclosed in their store listings. Specific instances included Huawei’s HMS Core in twelve apps, raising concerns about remote code updat
Analysis
TL;DR
- A study of over 220 military-marketed apps revealed that more than one in eight contained software development kits (SDKs) from nations considered adversarial by the Pentagon, including China and Russia.
- Approximately 64% of the examined apps included third-party code capable of tracking user behavior and location, with 40% collecting or sharing more data than disclosed in their store listings.
- Specific instances included Huawei’s HMS Core in twelve apps, raising concerns about remote code updates that could transform dormant software into surveillance tools.
- Surveyed military-affiliated individuals expressed high discomfort with foreign code but lacked transparency mechanisms, as major app stores do not disclose the country of origin for embedded SDKs.
- Participants identified in-phone warnings for foreign code and stricter federal regulations on data brokers as the most effective mitigation strategies.
Why It Matters
This issue highlights a critical vulnerability in national security where commercial data brokerage practices inadvertently expose military personnel to espionage risks. For AI and cybersecurity practitioners, it underscores the necessity of supply chain transparency in software dependencies and the limitations of current privacy labels in detecting geopolitical risks embedded in third-party code.
Technical Details
- Scope: Analysis of 220+ apps marketed to US military personnel, sourced from Google Play and military subreddits, covering utility, banking, and social categories.
- SDK Prevalence: 64% of apps contained third-party SDKs; 76 distinct SDKs were traced to countries including China, Russia, Israel, India, and Germany.
- Adversarial Code: Roughly 7% of apps contained code from nations designated as cyber adversaries by the Pentagon; 12 apps specifically included Huawei’s HMS Core, which maps locations and stores media.
- Data Discrepancy: 40% of apps collected or shared data exceeding their public privacy disclosures, indicating a gap between stated and actual data practices.
- Transparency Gap: Neither Google Play Store Data Safety sections nor Apple App Store Privacy Labels provide information regarding the geographic origin of the software components within apps.
Industry Insight
- Supply Chain Security: Developers and platform providers must implement stricter auditing for third-party SDK origins, particularly for applications targeting sensitive demographics, to prevent inadvertent inclusion of adversarial code.
- Regulatory Pressure: The lack of transparency in app store privacy labels suggests a need for new regulatory standards requiring disclosure of SDK vendor nationality and data routing paths.
- User Awareness Tools: There is a clear market demand for automated detection tools that alert users to the presence of foreign or unknown third-party code, which could serve as a primary defense mechanism against data harvesting.
Disclaimer: The above content is generated by AI and is for reference only.