Site navigation

Report: 65% of Free VPNs Pose Critical Privacy Risks

Tom Quinn

,

VPN privacy
Researchers warn that free VPNs are undermining privacy promises, with many creating significant risk while giving users a false sense of security.

A new security study has uncovered critical vulnerabilities among the most popular free VPN apps, with researchers warning they are ‘riddled with flaws’ that put users’ privacy and personal data at risk.

Following a review of 800 free VPN apps for both Android and iOS, Zimperium zLabs found that more than 65% exhibited risky behaviours and APIs, such as the ability to capture screenshots of the user interface without restriction, which the researchers suggest gives providers a ‘surveillance vector’ extending far beyond network traffic.

More than a fifth (22%) of the free VPNs tested also displayed insecure activity launch, a flaw that allows attackers to potentially skip system security checks and misuse parts of an app to run hidden or unauthorised actions.

Zimperium’s study warns that this could leave the door open to phishing attacks using UI injection, when a malicious app might launch the VPN’s login screen outside of the normal app flow, or even bypass users entirely to make the app appear active even when it’s not.

Perhaps more concerning, the research revealed that a quarter of the apps investigated failed to include any valid privacy manifest, a developer-declared file that outlines how an app uses sensitive data and APIs – especially those that could impact user privacy.

Despite Apple’s rules requiring privacy manifests from developers, many apps remain opaque, which Zimperium argued undermines user consent, blocks vendor scrutiny, and conceals data flows that might allow for profiling, re-identification, or monetisation. All of which runs counter to the promise of privacy-first design.

Added to that, more than 40% of VPNs requested excessive, and in some instances unusual, permissions. 

Zimperium discovered that some apps requested system-level access, including the AUTHENTICATE_ACCOUNTS permission on Android, used to manage and authenticate accounts for a service like Google Account Manager, giving the VPN some control over a user’s digital identity.


Recommended


iOS apps didn’t fare much better, with the study finding free apps requesting the LOCATION_ALWAYS permission, allowing the VPN to access the device’s location at all times, even when the app is not in use, arguably an unnecessary level of oversight for a typical VPN.

Zimperium warned that these vulnerabilities are not only endangering individual users, but posing serious risks to businesses. With bring-your-own-device (BYOD) policies still fairly common, even widely used free VPNs are opening up security gaps inside corporate networks, despite being seen as frontline protection.

“Our research makes one thing clear: not all VPN apps can be trusted,” concludes the study.

“While VPNs are often considered a primary line of defence, a critical distinction must be made: not all VPNs are created equal, especially free VPNs. While reputable solutions offer robust protection, many others can introduce significant risk to both the user and the organisation, all while providing a dangerous and false sense of security.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data