Study finds 25 per cent of Android apps to be a security risk

A review by Bit9 of Android Apps in the Google Play market found over 100,000 that are "questionable" or "suspicious"

According to a new report from Bit9--a security vendor with a focus on defending against advanced persistent threats (APT)--there is a one in four chance that downloading an Android app from the official Google Play market could put you at risk. Bit9 analyzed 400,000 or so apps in Google Play, and found over 100,000 it considers to be on the shady side.

Does that mean that the sky is falling, and everyone with an Android smartphone or tablet should abandon it immediately? No. The research by Bit9 illustrates some issues with app development in general, and should raise awareness among mobile users to exercise some discretion when downloading and installing apps, but it's not a sign of any urgent crisis affecting Android apps.

The report from Bit9 isn't about apps that contain malware, or are even overtly malicious for that matter. Bit9 reviewed the permissions requested by the apps, and examined the security and privacy implications of granting those permissions. The reality is that many apps request permission to access sensitive content they have no actual need for.

Bit9 says that 72 percent of all Android apps in the Google Play market request access to at least one potentially risky permission. For example, 42 percent request access to GPS location data, 31 percent want access to phone number and phone call history, and 26 percent ask for permission to access personal information. Bit9 discovered 285 apps that use 25 or more system permissions.

In addition to analyzing the apps in Google Play, Bit9 also surveyed IT decision managers about the mobile usage and security policies in place. The survey found that 71 percent of organizations allow employee-owned devices to connect to the company network, and 96 percent of those allow employees to access company email from a personal mobile device.

When you combine the two--the number of potentially risky apps, and the access companies grant personal mobile devices--it represents a security concern for organizations. When an employee allows an app to access sensitive information on a mobile device that is connected to the company network or email, it could expose customer, employee, or other company-owned data to the app.

Again, it's possible that all of the "offending" apps are legitimate, and that none of them pose any significant security risk. The issue is that apps with access to personal information and sensitive data have the potential to be a security risk--either intentionally or inadvertently--and many apps don't have a valid need for the access.

Keep in mind that the issue is not limited to Android. The Bit9 report focuses on Google Play and Android apps, but the problem stems from poorly developed apps, and users who blindly accept whatever permissions are requested without considering the implications.

Use caution. Next time you download some arcade game app, think twice about whether it really needs access to your GPS location data. If you download a music playing app, ask yourself if it really needs permission to access all of your contacts and personal information. Make sure you know what permissions you are granting before you tap to accept them, and don't install apps that require questionable or suspicious access to your device.

Join the PC World newsletter!

Error: Please check your email address.

Tags consumer electronicsappsGooglesecurityBit9smartphonesAndroidbusiness security

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tony Bradley

PC World (US online)
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?