Chinese and Russian code found in US military apps

A Purdue University study reveals that nearly two-thirds of Android apps for US military personnel contain third-party code from adversarial nations, including China and Russia.

By Central
The study found that 64% of military apps have third-party code, with 7% traced to adversarial nations.
Highlights
  • Nearly two-thirds of Android apps for US military personnel contain third-party tracking code from adversarial nations like China and Russia.
  • Huawei's HMS Core was found in twelve apps, including those for state National Guard organizations.
  • The study warns that SDKs can be updated remotely, potentially turning dormant code into surveillance tools.

A new academic study has uncovered that nearly two-thirds of Android apps designed for and marketed to US military personnel contain third-party code capable of tracking user behavior and location, with a small but significant percentage of that code tracing back to nations considered adversarial by the Pentagon, including China and Russia. Researchers from Purdue University analyzed more than 220 apps sourced from the Google Play store and military-focused subreddits, revealing a troubling gap between the data these applications actually collect and what their privacy disclosures promise.

Study Reveals Widespread Third-Party Code in Military Apps

The analysis, led by Purdue PhD researcher Joshua Shinkle, examined apps ranging from uniform guides and promotion-exam prep tools to banking and dating applications. Of the more than 220 apps surveyed, 64 percent contained third-party software development kits (SDKs), prebuilt components typically used for analytics and advertising that can also track user location and transmit behavioral data to external companies. The researchers found that 40 percent of the apps collected or shared more data than their Google or Apple store listings disclosed to users.

Adversarial Code Found in Apps Used by National Guard

While the most common SDKs originated from Google and Facebook, the study identified 76 distinct SDKs in total, with code traced to China, Russia, Israel, India, Germany, and other nations. Roughly 7 percent of the apps carried third-party code from a country the Pentagon classifies as adversarial. Notably, twelve of the apps contained Huawei’s HMS Core, a software kit that advertises capabilities for mapping user locations, delivering advertisements, and storing images and video. Several of these apps were built specifically for state National Guard organizations.

The researchers did not observe data being actively transmitted to Huawei servers during their testing. However, the study highlights a critical security concern: an SDK can be updated remotely at any time, meaning code that remains dormant today could be repurposed for surveillance or data exfiltration tomorrow. In at least one documented case, the Huawei code was incorporated into an app without the developer’s knowledge, having been smuggled in as a dependency within a commercial notification tool. This supply-chain vector represents a particularly insidious risk for applications used by military personnel.

What This Means for Military-Affiliated Users

The findings underscore a fundamental vulnerability in the app ecosystem used by service members. SDKs are often treated as black-box components by developers, who may not fully audit the dependencies they include. For military personnel, the stakes are uniquely high. Location data, usage patterns, and personal information collected through seemingly innocuous apps could, in aggregate, reveal operational habits, deployment locations, or unit affiliations.

Shinkle stated that the research aims to help military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourage continued discussion about how to address these gaps. The study serves as a concrete warning that the software supply chain for military-oriented applications lacks the transparency and security controls that national security contexts demand.

How to Mitigate Exposure from Third-Party Code

For military-affiliated users and anyone concerned about app privacy, the most immediate step is to audit the applications on your device. Review permissions regularly and revoke anything that seems excessive for the app’s stated function. Consider using a reputable privacy-focused security solution that monitors app behavior for unusual data access patterns. For developers building applications in sensitive contexts, implementing a rigorous software supply chain security policy is essential. This includes auditing all SDKs and their dependencies, verifying the provenance of every third-party component, and monitoring for updates or changes that could introduce new tracking capabilities.

What Affected Users Should Do Now

If you are a military member or work in a defense-related role, take these actions today: remove any apps that request unnecessary permissions, especially location access, from your primary device. Limit the use of personal mobile applications for official or operational purposes. Enable two-factor authentication on all accounts where it is available. Monitor your accounts for unusual activity, particularly if you have used apps that may have over-collected data. For organizations, the study reinforces the need for internal policies that restrict the use of unvetted third-party applications on devices with access to sensitive information. The presence of adversary-linked code in National Guard apps is not a hypothetical risk; it is a documented reality that demands immediate attention from both individual users and institutional decision-makers.

Share This Article