A group of security analysts has released a disturbing alert regarding over 20 popular Android VPN applications found on the Google Play Store. The research indicates that three distinct categories of VPN clients available on Google Play utilize the same infrastructures and source code, even though they appear as separate entities in Google’s app marketplace. Moreover, due to these shared characteristics, particularly in the source code, the security experts assert that they all possess the same security vulnerabilities.
This situation raises significant alarms, particularly regarding the lack of transparency connecting more than 20 of the most downloaded VPNs on Google Play. The researchers highlight the concerning fact that these VPNs create an illusion of choice for consumers, presenting themselves as unique, rival VPN services, while, at their core, they are fundamentally identical.
Additionally, all these VPNs share identical security weaknesses. As TechRadar points out, these vulnerabilities enable hackers to more easily decrypt user traffic and execute other attacks, meaning that regardless of the VPN you choose, you still risk exposure to the potential exploitation of these flaws. Some of these applications have even been associated with Russia and China, prompting further worries about their data collection practices involving U.S. citizens.