Tuesday, 21 July 2026
Rīga TV

World and Latvian news in one place

WorldPublished: 20 July 2026 at 12:37

Apps Marketed to US Troops Contain Chinese and Russian Code

A study found that more than one in eight mobile apps marketed to US military personnel contain software from China, Russia, or other foreign nations, raising data security concerns.

Foto: Wired

Researchers from Purdue University, the US Military Academy at West Point, and Florida International University examined over 220 mobile apps marketed to US service members. They found that more than one in eight contained third-party code from China, Russia, or other foreign countries. One popular app used by soldiers to rate living conditions on bases includes code from Huawei, flagged as a national security threat by US regulators in 2020. Two other apps incorporate the Russian ad service Yandex.

Nearly two-thirds (64%) of the apps contained third-party SDKs—prebuilt software components typically used for analytics and advertising that can also track user behavior and location. Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings. Of the 76 SDKs found, some traced back to China, Russia, Israel, India, Germany, and others. Roughly 7% of the apps carried code from nations considered adversarial by the Pentagon.

Twelve apps contained HMS Core, a Huawei software kit that can map user locations, deliver ads, and store images and video. Although no data was observed being sent to Huawei servers, an SDK can be updated remotely, meaning dormant code could become spyware later. In one case, the Huawei code was included without the developer's knowledge, smuggled in as a dependency in a commercial notification tool.

The researchers also surveyed 103 military-affiliated Americans—active-duty, reservists, veterans, DoD civilians, and families. Over 83% used at least one app with data practices that made them uncomfortable. On average, participants used more than three such apps. Between 76% and 83% were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea—the four nations the Pentagon designates as cyber adversaries. However, users have no easy way to know which apps carry such code, as app stores do not disclose the country of origin of the software inside an app.

Nearly two-thirds of participants said they had received little or no institutional guidance on personal app use. Of those who received some, nearly three-quarters called it inadequate. The Pentagon declined to comment. Participants ranked in-phone warnings—alerts when foreign or unknown third-party code is present—as both the most effective and most likely to gain support. Other mitigations drawing nearly identical support include a federal law restricting data brokers from buying or selling data on military personnel, independent audits of app privacy disclosures, and stricter bans on foreign code in military-marketed apps.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category