logo
Study Reveals Foreign Code in Apps Targeting US Military Personnel
Technology iconTechnology20 Jul 2026

Study Reveals Foreign Code in Apps Targeting US Military Personnel

A study finds apps marketed to US military personnel contain alarming amounts of foreign code, highlighting data privacy concerns.

Alarming Foreign Code in Military Apps

A recent study has uncovered that more than 12% of mobile applications marketed to US military personnel include software components developed in China, Russia, and other countries of concern. This revelation raises significant data privacy issues as foreign governments could potentially harvest sensitive information regarding service members' locations and activities.

Study Overview

The investigation was conducted by researchers at Purdue University, the US Military Academy at West Point, and Florida International University. They examined over 220 apps, which are commonly used by military personnel for various purposes, from rating base living conditions to banking and dating. The findings indicate that 64% of these applications were utilizing third-party software components, known as SDKs, that can track user behavior, including their precise locations.

Among the apps analyzed, some were found to contain code from companies like Huawei, identified as a national security threat by US regulators. The presence of these foreign components has raised concerns among military users, many of whom reported feeling uncomfortable with the potential risks associated with such software.

Risks of Data Exposure

The unregulated nature of the advertising technology sector exacerbates these risks. Civilians and military personnel are often treated similarly in this space, despite evidence that data exposure can lead to the uncovering of troop deployments and sensitive operational details. Previous reports have shown that location data gathered from common apps can trace military personnel to their homes and other restricted areas, making them vulnerable to foreign surveillance.

In April, US Central Command acknowledged receiving multiple reports about adversaries using commercial location data to target American forces. This was the first time the Pentagon confirmed that operational personnel could be hunted through the commercial data-broker economy.

Findings from the Study

The Purdue study’s lead author, Joshua Shinkle, expressed hope that their research would prompt more informed privacy decisions amongst military developers and platforms. Key findings from their examination include:

  • Nearly two-thirds of the apps (64%) utilized SDKs that share user data with external companies.
  • Approximately 40% of the analyzed apps shared more data than was disclosed in their app store listings.
  • Twelve of the apps contained Huawei's HMS Core, capable of location mapping and ad delivery.

While the researchers did not observe any immediate data transmission to Huawei servers, the nature of SDKs allows for remote updates, making dormant code a potential future risk.

User Sentiment and Recommendations

During the study, a survey involving 103 military-affiliated individuals revealed that over 83% of participants had used at least one app that collected data in ways they found concerning. Notably, 76-83% expressed extreme discomfort concerning apps that incorporated code from countries labeled as cyber adversaries, such as China and Russia. Many participants were unaware of which apps were integrated with foreign codes, as this information is not readily available in app store privacy disclosures.

Amidst these privacy concerns, roughly two-thirds of respondents indicated that they had received minimal guidance from military institutions regarding acceptable app use, further compounding the issue.

In terms of potential solutions, participants favored in-phone warning systems that notify users when foreign or unknown third-party code is present. Legislative measures to restrict data brokers from selling data related to military personnel were also met with strong support.

Conclusion

The current findings necessitate urgent attention from the military and concerned stakeholders to address the privacy vulnerabilities presented by foreign code in apps targeting service members. Greater awareness and better regulatory practices are crucial to protect military personnel from data security threats posed by adversarial nations.

Popular news

A double earthquake in Peru's Junin region has left five dead and many displaced, prompting extensive rescue operations and community support.

Subscribe to
our news

Get the most important updates and top stories in your inbox.

mail