A new security study has uncovered critical vulnerabilities among the most popular free VPN apps, with researchers warning they are ‘riddled with flaws’ that put users’ privacy and personal data at risk.
Following a review of 800 free VPN apps for both Android and iOS, Zimperium zLabs found that more than 65% exhibited risky behaviours and APIs, such as the ability to capture screenshots of the user interface without restriction, which the researchers suggest gives providers a ‘surveillance vector’ extending far beyond network traffic.
More than a fifth (22%) of the free VPNs tested also displayed insecure activity launch, a flaw that allows attackers to potentially skip system security checks and misuse parts of an app to run hidden or unauthorised actions.
Zimperium’s study warns that this could leave the door open to phishing attacks using UI injection, when a malicious app might launch the VPN’s login screen outside of the normal app flow, or even bypass users entirely to make the app appear active even when it’s not.
Perhaps more concerning, the research revealed that a quarter of the apps investigated failed to include any valid privacy manifest, a developer-declared file that outlines how an app uses sensitive data and APIs – especially those that could impact user privacy.
Despite Apple’s rules requiring privacy manifests from developers, many apps remain opaque, which Zimperium argued undermines user consent, blocks vendor scrutiny, and conceals data flows that might allow for profiling, re-identification, or monetisation. All of which runs counter to the promise of privacy-first design.
Added to that, more than 40% of VPNs requested excessive, and in some instances unusual, permissions.
Zimperium discovered that some apps requested system-level access, including the AUTHENTICATE_ACCOUNTS permission on Android, used to manage and authenticate accounts for a service like Google Account Manager, giving the VPN some control over a user’s digital identity.
Recommended
- VPN Sign-ups Surge As Ofcom Age Checks Come Into Effect
- UK VPN Crackdown Could Backfire, Warn Campaigners
- VPN Security Fears Pushing Firms To ‘Zero Trust Everywhere’
iOS apps didn’t fare much better, with the study finding free apps requesting the LOCATION_ALWAYS permission, allowing the VPN to access the device’s location at all times, even when the app is not in use, arguably an unnecessary level of oversight for a typical VPN.
Zimperium warned that these vulnerabilities are not only endangering individual users, but posing serious risks to businesses. With bring-your-own-device (BYOD) policies still fairly common, even widely used free VPNs are opening up security gaps inside corporate networks, despite being seen as frontline protection.
“Our research makes one thing clear: not all VPN apps can be trusted,” concludes the study.
“While VPNs are often considered a primary line of defence, a critical distinction must be made: not all VPNs are created equal, especially free VPNs. While reputable solutions offer robust protection, many others can introduce significant risk to both the user and the organisation, all while providing a dangerous and false sense of security.”





