The Top10VPN publication, which specializes in reviewing and testing VPN services, conducted a study of the 100 most popular free VPN apps for the Android platform, totaling over 2.5 billion installations (the study examined 100 free VPN apps with the highest download counts recorded in the Google Play catalog). Key findings:
- 88 of the tested programs had various issues leading to information leaks. In 83 apps, leaks occurred due to access to third-party DNS servers (not the provider's servers), for example, DNS Google was used in 40 cases and Cloudflare in 14. In 79 apps, there was no assurance that traffic would not be sent outside the VPN. In 17 apps, multiple types of leaks were identified (revealing the user's source IPv4 and IPv6 addresses to websites, leaks through DNS and WebRTC). VPNIn 11 apps, outdated pseudo-random number generators were discovered. One app did not employ traffic encryption at all. In 35 applications, outdated cryptographic algorithms were used (only 20 apps employed reliable hashing methods). In 23 apps, during the establishment of a VPN tunnel to connect to an external server, old versions of TLS (older than TLSv3) were allowed, and 6 apps used SSLv2.
- In 69 programs, excessive permissions were requested; for example, 20 apps required access to location data (ACCESS_*_LOCATION), 46 requested access to the list of installed programs (QUERY_ALL_PACKAGES), 9 sought access to phone status (READ_PHONE_STATE, which among other things allows for retrieving IMEI and IMSI), 82 requested unique identifiers for identification in advertising networks (ACCESS_ADVERTISEMENTS_ID), and 10 attempted to access the camera.
- In 53 apps, proprietary third-party functions were identified; for instance, 13 programs used code for tracking locations, 31 for retrieving identifiers for advertising networks, and 22 for checking other installed applications.
- 80 programs utilized third-party libraries, among which 15 used libraries from Bytedance (TikTok), while 11 used Yandex libraries.
84 applications included SDK components from marketing platforms or social networks, with 16 apps incorporating 10 or more such components. - 84 applications included SDK components from marketing platforms or social networks, with 16 apps including 10 or more such components.
- 32 applications were found to access hardware capabilities and sensors that could compromise privacy. For example, 15 applications access the camera, 7 the microphone, and 14 mechanisms for determining location, such as GPS, with 14 accessing sensors (gyroscope, proximity sensor, etc.).
- 71 applications sent personal data to third-party services, such as Facebook (47), Yandex (13), and VK (11). 37 programs revealed device identifiers, 23 - an IP address, and 61 - unique tracking identifiers. 19 applications sent telemetry with device and system information to VPN provider servers, and 56 to third-party services, such as Google (39), Facebook (17), and Yandex (9).

- 19 applications were found to have malware in checks using VirusTotal, which employs over 70 antivirus engines. 18 applications showed connections to domains, and 13 to IP addresses, listed in blacklists of malicious hosts and addresses.
- 93 applications revealed discrepancies between stated privacy compliance tags and actual conditions. 75 applications
incorrectly informed about user data collection methods, 64 about sending data to third-party services, and 32 about employed security methods. Of 65 applications labeled 'No Data Sharing', only 20 prevented sending data to third-party services, while of 32 applications labeled 'No Data Collection', only two met the associated requirements.
Source: opennet.ru

