Search

Thousands of Android, iOS Apps Expose User Data Due to Cloud Misconfigurations: Zimperium

Zimperium found cloud misconfiguration problems on 14 percent of the total testing base of more than 1.3 million Android and iOS apps.

Advertisement
Highlights
  • Apps were exposing even SSH keys and system details in some cases
  • Zimperium said the issues could allow bad actors to conduct frauds
  • The company reached some developers but received minimal response
Thousands of Android, iOS Apps Expose User Data Due to Cloud Misconfigurations: Zimperium

Android and iOS apps were leaking personally identifiable information (PII), Zimperium researchers found

Photo Credit: Pexels/ Amarnath Radhakrishnan

Thousands of Android and iOS apps exposed user data due to commonly found cloud misconfigurations, according to a mobile security firm. The issues could allow malicious attackers to exploit the leaked information. The researchers found misconfiguration problems on apps using popular public cloud services such as Amazon Web Services, Google Cloud, and Microsoft Azure. Among other apps, a mobile wallet developed by a Fortune 500 company was spotted exposing session and payment information of users that could lead to fraud.

The researchers at Zimperium conducted an automated analysis of more than 1.3 million Android and iOS apps in which they found misconfiguration problems on 14 percent of the total testing base. In a blog post, the company noted that it detected apps that leak the entire cloud infrastructure scripts and definitions including SSH keys.

“Other types of configurations are Web server config files, installation files, and even passwords to payment kiosks,” the company said in the post.

The apps were found to expose personally identifiable information (PII) including profile pictures, personal details, and medical test data. Some apps even enabled fraud or exposed intellectual property (IP) data and internal systems.

Apps exposing PII included some medical and social media apps as well as a major game app and a fitness app. Major city transportation, online retailer, and gambling apps were also noticed enabling fraud. Further, major music, news service, mobile payments wallet, airport, hardware developer, and Asian government travel apps were found to expose IP and system details. Zimperium, however, didn't reveal the exact name of the apps exposing data.

“During our review, we encountered several apps relying on both Google and Amazon storage that was accessible without any security. In one example, the information we were able to obtain included profile pictures and other PII information,” Zimperium said.

The researchers also found that in some cases, the misconfigurations allowed hackers to even change or overwrite data that could bring further disruption for end users.

Wired reported that a total of 11,877 Android apps and 6,608 iOS apps were exposing users' sensitive information through common cloud misconfigurations.

The researchers contacted some app developers about the exposures, though many apps were found to have still exposed data. The response from most of the app developers reached out was also minimal.

Cloud service providers such as Amazon, Google, and Microsoft do provide ways to protect data from being exposed. However, it is the ultimate responsibility of developers and the companies that offer apps to use appropriate configurations to ensure safety of their users.

“Once you've closed off your cloud service to unauthorised external access, the next thing you can do is to use a service that assesses your secure software development lifecycle as part of your standard development process,” Zimperium said.

Importantly, Zimperium is one of the three mobile security companies that are a part of Google's App Defense Alliance initiative, that is aimed to offer automated app scanning for Google Play.

Wired reported that Zimperium researchers used the same set of tools it uses for the App Defense Alliance programme to investigate cloud misconfigurations. However, instead of looking for accidental exposures, the company uses the tools for Google Play to find potentially malicious functionality.


Does WhatsApp's new privacy policy spell the end for your privacy? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 13T Confirmed to Have a 6,260mAh Glacier Battery 
  2. Motorola Edge 60, Edge 60s Monikers Confirmed Via HDR10+ Certification Site
  3. CMF Phone 2 Pro Will Come With AI-Powered Essential Space Feature
  4. Nothing's CMF Phone 2 Pro Teasers Reveal Design
  5. Vivo X200 Ultra With 200-Megapixel Telephoto Camera Launched
  6. Amazfit Active 2 India Launch Date, Design and Key Features Confirmed
  7. Google Brings Changes to Clock Font and Spacing With Android 16 Beta 4
  8. HMD Barbie Phone Goes on Sale in India Today: See Price
  9. Samsung Galaxy Z Fold 7, Galaxy Z Flip 7 Progressing as per Schedule: Report
  10. Samsung Announces Second Edition of 'Walk-a-thon India' Challenge
  1. Iran’s Folded Rocks Reveal Ancient Tectonic Power at Asia-Europe Boundary
  2. Astronomers Discover Potential ‘Dark Galaxy’ Near the Milky Way
  3. Motorola Solutions Launches AI Tool, New Device to Cut Emergency Response Time
  4. Samsung Announces Second Edition of ‘Walk-a-thon India’ Challenge; Galaxy Watch Ultra Offered as Top Prize
  5. Vivo X200 Ultra With Snapdragon 8 Elite SoC, 200-Megapixel Telephoto Camera Launched: Price, Specifications
  6. Google Teases AI Glasses in a Live Demo, Hints at Future Gemini Features
  7. Huawei Said to be Readying New AI Chip for Mass Shipment as China Seeks Nvidia Alternatives
  8. Google Settles India's Antitrust Probe in Android TV Case
  9. Vivo X200s With MediaTek Dimensity 9400+ SoC, 6,200mAh Battery Launched: Price, Features
  10. Airtel’s AI-Powered Spam Detection Expanded to Indian Regional Languages, International Calls and SMSes
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »