{"id":495335,"date":"2026-02-24T02:21:10","date_gmt":"2026-02-24T02:21:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/495335\/"},"modified":"2026-02-24T02:21:10","modified_gmt":"2026-02-24T02:21:10","slug":"android-mental-health-apps-with-14-7m-installs-filled-with-security-flaws","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/495335\/","title":{"rendered":"Android mental health apps with 14.7M installs filled with security flaws"},"content":{"rendered":"<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" alt=\"Android mental health apps with 14.7M installs filled with security flaws\" height=\"900\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/02\/mental-health.jpg\" width=\"1600\"\/><\/p>\n<p>Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users\u2019 sensitive medical information.<\/p>\n<p>In one of the apps, security researchers discovered more than 85 medium- and high-severity vulnerabilities that could be exploited to compromise users\u2019 therapy data and privacy.<\/p>\n<p>Some of the products are AI companions designed to help people suffering from clinical depression, multiple forms of anxiety, panic attacks, stress, and bipolar disorder.<\/p>\n<p> <a href=\"https:\/\/www.wiz.io\/lp\/ai-security-board-report-template?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY26Q4_INB_FORM_AI-Security-Board-Report-Template&amp;sfcid=701Vh00000Wn7E1IAJ&amp;utm_term=FY27-bleepingcomputer-article-970x250&amp;utm_content=AI-Board-Report\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/02\/ai-security-board-report-template.jpg\" alt=\"Wiz\" style=\"margin-top: 0px;\"\/><\/a><\/p>\n<p>At least six of the ten analyzed apps state that user conversations or chats remain private, or are encrypted securely on the vendor\u2019s servers.<\/p>\n<p>\u201cMental health data carries unique risks. On the dark web, therapy records sell for $1,000 or more per record, far more than credit card numbers,\u201d says Sergey Toshin, founder of mobile security company Oversecured.<\/p>\n<p>Over 1,500 security issues found<\/p>\n<p>Oversecured scanned ten mobile apps advertised as tools that can help with various mental health problems, and uncovered a total of 1,575 security vulnerabilities (54 rated high-severity, 538 medium-severity, and 983 low-severity).<\/p>\n<p>\u00a0&#13;<br \/>\n\t\t\tApp Type&#13;<br \/>\n\t\t\tInstalls&#13;<br \/>\n\t\t\tHigh&#13;<br \/>\n\t\t\tMedium&#13;<br \/>\n\t\t\tLow&#13;<br \/>\n\t\t\tTotal&#13;<br \/>\n\t\t\tScan date&#13;<br \/>\n\t\t01&#13;<br \/>\n\t\t\tMood &amp; habit tracker&#13;<br \/>\n\t\t\t10M+&#13;<br \/>\n\t\t\t1&#13;<br \/>\n\t\t\t147&#13;<br \/>\n\t\t\t189&#13;<br \/>\n\t\t\t337&#13;<br \/>\n\t\t\t01\/23\/2026&#13;<br \/>\n\t\t02&#13;<br \/>\n\t\t\tAI therapy chatbot&#13;<br \/>\n\t\t\t1M+&#13;<br \/>\n\t\t\t23&#13;<br \/>\n\t\t\t63&#13;<br \/>\n\t\t\t169&#13;<br \/>\n\t\t\t255&#13;<br \/>\n\t\t\t01\/22\/2026&#13;<br \/>\n\t\t03&#13;<br \/>\n\t\t\tAI emotional health platform&#13;<br \/>\n\t\t\t1M+&#13;<br \/>\n\t\t\t13&#13;<br \/>\n\t\t\t124&#13;<br \/>\n\t\t\t78&#13;<br \/>\n\t\t\t215&#13;<br \/>\n\t\t\t01\/23\/2026&#13;<br \/>\n\t\t04&#13;<br \/>\n\t\t\tHealth &amp; symptom tracker&#13;<br \/>\n\t\t\t500k+&#13;<br \/>\n\t\t\t7&#13;<br \/>\n\t\t\t31&#13;<br \/>\n\t\t\t173&#13;<br \/>\n\t\t\t211&#13;<br \/>\n\t\t\t01\/22\/2026&#13;<br \/>\n\t\t05&#13;<br \/>\n\t\t\tDepression management tool&#13;<br \/>\n\t\t\t100k+&#13;<br \/>\n\t\t\t-&#13;<br \/>\n\t\t\t66&#13;<br \/>\n\t\t\t91&#13;<br \/>\n\t\t\t157&#13;<br \/>\n\t\t\t01\/23\/2026&#13;<br \/>\n\t\t06&#13;<br \/>\n\t\t\tCBT-based anxiety app&#13;<br \/>\n\t\t\t500k+&#13;<br \/>\n\t\t\t3&#13;<br \/>\n\t\t\t45&#13;<br \/>\n\t\t\t62&#13;<br \/>\n\t\t\t110&#13;<br \/>\n\t\t\t01\/22\/2026&#13;<br \/>\n\t\t07&#13;<br \/>\n\t\t\tOnline therapy &amp; support community&#13;<br \/>\n\t\t\t1M+&#13;<br \/>\n\t\t\t7&#13;<br \/>\n\t\t\t20&#13;<br \/>\n\t\t\t71&#13;<br \/>\n\t\t\t98&#13;<br \/>\n\t\t\t01\/23\/2026&#13;<br \/>\n\t\t08&#13;<br \/>\n\t\t\tAnxiety &amp; phobia self-help&#13;<br \/>\n\t\t\t50k+&#13;<br \/>\n\t\t\t-&#13;<br \/>\n\t\t\t15&#13;<br \/>\n\t\t\t54&#13;<br \/>\n\t\t\t69&#13;<br \/>\n\t\t\t01\/22\/2026&#13;<br \/>\n\t\t09&#13;<br \/>\n\t\t\tMilitary stress management&#13;<br \/>\n\t\t\t50k+&#13;<br \/>\n\t\t\t-&#13;<br \/>\n\t\t\t12&#13;<br \/>\n\t\t\t50&#13;<br \/>\n\t\t\t62&#13;<br \/>\n\t\t\t01\/22\/2026&#13;<br \/>\n\t\t10&#13;<br \/>\n\t\t\tAI CBT chatbot&#13;<br \/>\n\t\t\t500k+&#13;<br \/>\n\t\t\t-&#13;<br \/>\n\t\t\t15&#13;<br \/>\n\t\t\t46&#13;<br \/>\n\t\t\t61&#13;<br \/>\n\t\t\t01\/23\/2026&#13;<\/p>\n<p>Although none of the discovered issues are critical, many can be leveraged to intercept login credentials, spoof notifications, HTML injection, or to locate the user.<\/p>\n<p>The researchers used the Oversecured scanner to check the APK files of the ten mental health applications for known vulnerability patterns in dozens of categories.<\/p>\n<p>In a report shared with BleepingComputer, the researchers say that some of the verified apps \u201cparse user-supplied URIs without adequate validation.\u201d<\/p>\n<p>One therapy app with more than one million downloads uses Intent.parseUri() on an externally controlled string and launches the resulting messaging object (intent) without validating the target component.<\/p>\n<p>This allows an attacker to force the app to open any internal activity, even if it is not intended for external access.<\/p>\n<p>\u201cSince these internal activities often handle authentication tokens and session data, exploitation could give an attacker access to a user\u2019s therapy records,\u201d Oversecured explains.<\/p>\n<p>Another issue is storing data locally in a way that gives read access to any app on the device. Depending on the saved information, this could expose therapy details, such as therapy entries, Cognitive Behavioral Therapy (CBT) session notes, and various scores.<\/p>\n<p>Oversecured states that they also discovered plaintext configuration data, including backend API endpoints and a hardcoded Firebase database URL, within the APK resources.<\/p>\n<p>Furthermore, some of the vulnerable apps use the cryptographically insecure java.util.Random class for generating session tokens or encryption keys.<\/p>\n<p>According to the researchers, \u201cmost of the 10 apps lack any form of root detection.\u201d On a rooted (jailbroken) device, any app with root privileges has access to all health data stored locally.<\/p>\n<p>Oversecured says that six of the ten analyzed apps \u201chad zero high-severity findings, but still carried medium-severity issues that weaken their overall security posture.\u201d<\/p>\n<p>\u201cThese apps collect and store some of the most sensitive personal data in mobile: therapy session transcripts, mood logs, medication schedules, self-harm indicators, and in some cases, information protected under HIPAA,\u201d the researchers note.<\/p>\n<p>From BleepingComputer\u2019s observations the collective download count for the apps scanned by Oversecured is more than\u00a014.7 million, and only four received an update as recently as this month. For the rest, the date of the latest update was as recent as\u00a0November 2025 or even September 2024.<\/p>\n<p>Oversecured\u2019s scans occurred between January 22 and 23 and targeted the latest app versions available at the time. The researchers cannot confirm if any of the uncovered vulnerabilities have been addressed.\u00a0<\/p>\n<p>BleepingComputer has refrained from the sharing the names of the impacted apps as the vulnerabilities are still being disclosed by Oversecured.<\/p>\n<p>        <a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored nofollow\"><br \/>\n            <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/02\/tines-in-art-square.jpg\" alt=\"tines\"\/><br \/>\n        <\/a><\/p>\n<p>Modern IT infrastructure moves faster than manual workflows can handle.<\/p>\n<p>In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.<\/p>\n<p>        <a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored nofollow\">Get the guide<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose&hellip;\n","protected":false},"author":2,"featured_media":495336,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[49,48,190,61],"class_list":{"0":"post-495335","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-ca","9":"tag-canada","10":"tag-mobile","11":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/495335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=495335"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/495335\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/495336"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=495335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=495335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=495335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}