A new academic study has raised concerns about the privacy and security of free Android virtual private network applications after researchers found that many of the most popular apps on Google Play Store fail to provide the protection users expect from VPN services. Researchers examined 281 widely used free VPN applications using a testing framework called MVPNalyzer and discovered numerous issues, including traffic leaks, unencrypted communications, and extensive user tracking. According to the study, applications containing at least one security or privacy problem have collectively been installed more than 2.4 billion times, highlighting the scale of potential exposure.
The research was presented at the Network and Distributed System Security Symposium in February 2026 by experts from University of Michigan, University of New Mexico, and IIT Delhi. MVPNalyzer was developed as a mobile counterpart to the researchers’ earlier work on desktop VPN software and is described as the first framework specifically designed to systematically evaluate Android VPN applications. The findings revealed that 29 applications allowed user traffic to leak outside encrypted tunnels, including Domain Name System requests that expose websites users visit. Another 61 applications transmitted certain information in plain text, making it accessible to anyone monitoring network traffic. Researchers identified five applications that downloaded their configuration files without encryption, a weakness that could allow attackers on the same network, such as public Wi Fi operators, to redirect users to malicious servers under their control. The researchers successfully demonstrated this attack in a controlled environment and said only two of the five affected providers responded and committed to implementing secure HTTPS protections.
The study also uncovered broader privacy issues among the tested applications. Of the 29 applications with leakage problems, 24 exposed DNS traffic and six leaked complete browsing traffic outside encrypted tunnels. Four applications were found to operate with no encryption at all. Researchers also discovered that 169 applications made no effort to disguise their VPN traffic, making them easy to identify and block by network operators or government censorship systems, despite many of these applications advertising their ability to bypass restrictions. User tracking was another significant concern. The researchers found that 76 applications transmitted the device’s advertising identifier, a unique code used by advertisers to track user activity across different applications. More than 80 percent of the applications, representing 246 apps, contacted known advertising and tracking services. Many also collected information such as device models, operating system versions, and screen sizes, which can be combined to create unique device fingerprints. One application was even found transmitting precise GPS coordinates.
A separate analysis of OpenVPN configuration files from 108 applications revealed additional weaknesses. Only one application complied with all the security best practices evaluated in the study. Nearly 89 percent of the tested applications relied on a single authentication method rather than combining multiple mechanisms, while almost one in five used weak or outdated encryption technologies, including Blowfish and Triple DES. Some applications even disabled encryption entirely. Researchers said these issues are largely the result of poor maintenance and insufficient oversight, noting that many of the applications remain highly ranked in Google Play Store and carry labels and verification badges that may give users a false sense of security. The findings align with previous studies that identified hidden connections between popular VPN applications, excessive data collection practices, and the use of outdated security libraries. Researchers advised users to exercise caution when selecting VPN services, favor providers that publish independent security audits, and avoid assuming that marketing claims such as “verified” or “no logs” automatically guarantee privacy and security protections.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





