LIVE NEWS
  • U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
  • Ukraine Splits up Weapons Making, Warns Europe Must Do the Same
  • Bookshelf: the untold story of a UN secretary-general
  • Lilly, Novo, Pfizer look to new weight loss drugs
  • From protest to silence: China’s long game in Zambia
  • ‘This might be the point of no return’: Experts on the current measles outbreak and where we go from here
  • 5 killed when Indian Air Force transport aircraft crashes in Assam
  • Legacy sportsbooks are chasing prediction markets that already trade billions each month
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Android mental health apps with 14.7M installs filled with security flaws
Cybersecurity

Android mental health apps with 14.7M installs filled with security flaws

primereportsBy primereportsFebruary 23, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Android mental health apps with 14.7M installs filled with security flaws
Share
Facebook Twitter LinkedIn Pinterest Email


Android mental health apps with 14.7M installs filled with security flaws

Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users’ sensitive medical information.

In one of the apps, security researchers discovered more than 85 medium- and high-severity vulnerabilities that could be exploited to compromise users’ therapy data and privacy.

Some of the products are AI companions designed to help people suffering from clinical depression, multiple forms of anxiety, panic attacks, stress, and bipolar disorder.

Wiz

At least six of the ten analyzed apps state that user conversations or chats remain private, or are encrypted securely on the vendor’s servers.

“Mental health data carries unique risks. On the dark web, therapy records sell for $1,000 or more per record, far more than credit card numbers,” says Sergey Toshin, founder of mobile security company Oversecured.

Over 1,500 security issues found

Oversecured scanned ten mobile apps advertised as tools that can help with various mental health problems, and uncovered a total of 1,575 security vulnerabilities (54 rated high-severity, 538 medium-severity, and 983 low-severity).












 App TypeInstallsHighMediumLowTotalScan date
01Mood & habit tracker10M+114718933701/23/2026
02AI therapy chatbot1M+236316925501/22/2026
03AI emotional health platform1M+131247821501/23/2026
04Health & symptom tracker500k+73117321101/22/2026
05Depression management tool100k+–669115701/23/2026
06CBT-based anxiety app500k+3456211001/22/2026
07Online therapy & support community1M+720719801/23/2026
08Anxiety & phobia self-help50k+–15546901/22/2026
09Military stress management50k+–12506201/22/2026
10AI CBT chatbot500k+–15466101/23/2026

Although none of the discovered issues are critical, many can be leveraged to intercept login credentials, spoof notifications, HTML injection, or to locate the user.

The researchers used the Oversecured scanner to check the APK files of the ten mental health applications for known vulnerability patterns in dozens of categories.

In a report shared with BleepingComputer, the researchers say that some of the verified apps “parse user-supplied URIs without adequate validation.”

One therapy app with more than one million downloads uses Intent.parseUri() on an externally controlled string and launches the resulting messaging object (intent) without validating the target component.

This allows an attacker to force the app to open any internal activity, even if it is not intended for external access.

“Since these internal activities often handle authentication tokens and session data, exploitation could give an attacker access to a user’s therapy records,” Oversecured explains.

Another issue is storing data locally in a way that gives read access to any app on the device. Depending on the saved information, this could expose therapy details, such as therapy entries, Cognitive Behavioral Therapy (CBT) session notes, and various scores.

Oversecured states that they also discovered plaintext configuration data, including backend API endpoints and a hardcoded Firebase database URL, within the APK resources.

Furthermore, some of the vulnerable apps use the cryptographically insecure java.util.Random class for generating session tokens or encryption keys.

According to the researchers, “most of the 10 apps lack any form of root detection.” On a rooted (jailbroken) device, any app with root privileges has access to all health data stored locally.

Oversecured says that six of the ten analyzed apps “had zero high-severity findings, but still carried medium-severity issues that weaken their overall security posture.”

“These apps collect and store some of the most sensitive personal data in mobile: therapy session transcripts, mood logs, medication schedules, self-harm indicators, and in some cases, information protected under HIPAA,” the researchers note.

From BleepingComputer’s observations the collective download count for the apps scanned by Oversecured is more than 14.7 million, and only four received an update as recently as this month. For the rest, the date of the latest update was as recent as November 2025 or even September 2024.

Oversecured’s scans occurred between January 22 and 23 and targeted the latest app versions available at the time. The researchers cannot confirm if any of the uncovered vulnerabilities have been addressed. 

BleepingComputer has refrained from the sharing the names of the impacted apps as the vulnerabilities are still being disclosed by Oversecured.


tines

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDeepSeek V4 Lite Surfaces With Breakthrough SVG Generation Skills
Next Article Winter Storm Updates: Heavy Snow, Blizzard Warnings in NYC, NJ and Boston – The New York Times
primereports
  • Website

Related Posts

Cybersecurity

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals

June 13, 2026
Cybersecurity

Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security

June 12, 2026
Cybersecurity

In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
  • Ukraine Splits up Weapons Making, Warns Europe Must Do the Same
  • Bookshelf: the untold story of a UN secretary-general
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.