Dernière minute
ARالمنتخب الإسباني يعود إلى مدريد بعد تتويجه بكأس العالم 2026 وسط استقبال تاريخيARالقيادة المركزية الأمريكية تستهدف مواقع إيرانية بعد هجمات الحرس الثوري في مضيق هرمزARالأسهم الكورية الجنوبية ترتفع مدعومة بأسهم الرقائق بعد خسائرARالحوثيون يعلنون "حصاراً بحرياً" على السعودية، والتحالف يتوعّد بالرد على أي تهديدARطهران تعلن "حرباً شاملة" مع واشنطن وتعطّل الملاحة في هرمز، وترامب يتوعّد إيران بثمن "أكبر بكثير"ARالجيش الأردني يعترض ثلاثة صواريخ إيرانيةARوزارة الخارجية الأمريكية تحذر مواطنيها في الشرق الأوسط من اضطرابات السفر واستهداف المصالحARروسيا وأوكرانيا تستعدان لتبادل "بالغ الأهمية" للأسرىARترمب يفرض رسوماً جمركية جديدة على سلع كنديةARتدريبات صينية بالذخيرة الحية قرب جزيرة يابانية بمشاركة روسيةARالمنتخب الإسباني يعود إلى مدريد بعد تتويجه بكأس العالم 2026 وسط استقبال تاريخيARالقيادة المركزية الأمريكية تستهدف مواقع إيرانية بعد هجمات الحرس الثوري في مضيق هرمزARالأسهم الكورية الجنوبية ترتفع مدعومة بأسهم الرقائق بعد خسائرARالحوثيون يعلنون "حصاراً بحرياً" على السعودية، والتحالف يتوعّد بالرد على أي تهديدARطهران تعلن "حرباً شاملة" مع واشنطن وتعطّل الملاحة في هرمز، وترامب يتوعّد إيران بثمن "أكبر بكثير"ARالجيش الأردني يعترض ثلاثة صواريخ إيرانيةARوزارة الخارجية الأمريكية تحذر مواطنيها في الشرق الأوسط من اضطرابات السفر واستهداف المصالحARروسيا وأوكرانيا تستعدان لتبادل "بالغ الأهمية" للأسرىARترمب يفرض رسوماً جمركية جديدة على سلع كنديةARتدريبات صينية بالذخيرة الحية قرب جزيرة يابانية بمشاركة روسية
Newsgather
RetourUS Military Apps Contain Foreign-Made Software, Raising Data Security Concerns
US Military Apps Contain Foreign-Made Software, Raising Data Security Concerns
En développement
Wiredil y a 18 heuresDefense5 min de lecture

US Military Apps Contain Foreign-Made Software, Raising Data Security Concerns

L'essentiel

A study found over 1 in 8 mobile apps for US military personnel contain software from China, Russia, or other foreign nations, raising national security concerns about data harvesting and potential targeting of service members.

Résumé généré par IA

Pourquoi c'est important

A new study reveals that over one in eight mobile apps marketed to US military personnel contain software from foreign nations, including China and Russia, raising concerns about data harvesting. This follows previous warnings and confirmed instances of adversaries exploiting commercial location data to target US personnel in the Middle East.

Taille de police

A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China, Russia, or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work, and deploy.

According to researchers at Purdue University, the US Military Academy at West Point, and Florida International University, one popular app used by service members to rate living conditions on their own bases include code from Huawei, the Chinese telecom that US regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian ad service Yandex.

The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the same—unless there is profit in telling them apart—despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.

WIRED investigations have previously shown location data harvested from ordinary apps tracing US service members to their homes, their children's schools, and off-base establishments where troops are prohibited from being seen. Experts have warned the same data could aid foreign spies in identifying personnel with access to sensitive sites, map when a facility is least guarded, or surface other compromising details.

The stakes are no longer hypothetical. In April, US Central Command acknowledged in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East, where US forces remain locked in a standoff with the Iranian military over the Strait of Hormuz. Lawmakers called it the first official confirmation that troops in an active war zone were being hunted through the data-broker economy—a threat the Pentagon's own contractors and researchers had warned about for nearly a decade.

The new study takes a first look at one piece of that exposure: what actually sits inside the apps built and marketed specifically for the military.

"We are grateful for the opportunity to bring greater attention to these issues,” says Joshua Shinkle, a Purdue University PhD researcher and the study’s lead author. “We hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourages continued discussion with developers, platforms, and policymakers about how to address these gaps.”

The researchers examined more than 220 such apps—from uniform guides and promotion-exam prep to banking and dating apps—pulled from the Google Play store and military subreddits. Nearly two-thirds—or 64 percent—contained third-party code, known as SDKs: prebuilt software components, typically used for analytics and advertising, that can also track user behavior, including their locations, and share that information with outside companies.

Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings, the researchers found.

The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising. But 76 turned up in all, including code traced back to China, Russia, Israel, India, Germany, and others. Roughly 7 percent of the apps carried third-party code from a nation considered adversarial by the Pentagon.

Twelve of the apps contained HMS Core, a Huawei software kit that advertises the ability to map user locations, deliver ads, and store images and video. Several were built for state National Guard organizations.

The researchers observed no data actually going to Huawei servers. But an SDK can be updated remotely at any time. Code that is dormant today can still be spyware tomorrow. In at least one case, noted by the study, the Huawei code arrived without the app’s developer’s knowledge, smuggled in as a dependency in a commercial notification tool.

The researchers also surveyed 103 military-affiliated Americans—active-duty service members, reservists, veterans, DoD civilians, and their families—about the data practices they encountered on their own phones. More than 83 percent used at least one app engaging in data practices they said made them uncomfortable. On average, those participants used more than three such apps.

Between 76 and 83 percent of participants said they were extremely uncomfortable with apps containing code from China, Russia, Iran, or North Korea—the four nations the Pentagon designates as cyber adversaries. But no user has a straightforward way to know which apps carry such code. Neither Google's Play Store Data Safety section nor Apple's App Store Privacy Labels disclose the country of origin of the software running inside an app.

Participants reported being more comfortable with data collection when an app was branded for military use.

Meanwhile, nearly two-thirds said they had received little or no institutional guidance on personal app use. Of those who had received some, nearly three-quarters called it inadequate.

The Pentagon declined to comment.

Asked to weigh potential mitigations, participants ranked in-phone warnings—alerts when foreign or unknown third-party code is present in an installed app—as both the most effective and the most likely for them to support.

A federal law restricting data brokers from buying or selling data on military-affiliated personnel, independent audits of app privacy disclosures, and stricter bans on foreign code in military-marketed apps drew nearly identical support.

À surveiller

Perspective IA — des possibilités, pas des certitudes

  • Lawmakers will likely push for new legislation restricting data brokers and foreign code in military-marketed apps.

    Probable · En quelques mois

  • The Pentagon will likely issue updated guidance on personal app use for military personnel.

    Probable · En quelques mois

Questions ouvertes

  • How will the Pentagon respond to the study's findings?
  • What specific policy changes will be implemented to mitigate this risk?
  • How will app stores address the lack of transparency regarding software origin?

Sujets liés

This article was originally published by Wired.

Articles liés

US Conducts 10th Night of Strikes Against Iran Amid Escalating Tensions and Retaliation Claims
En développement·il y a 3 heures

US Conducts 10th Night of Strikes Against Iran Amid Escalating Tensions and Retaliation Claims

The US has carried out its 10th consecutive night of strikes against Iran, targeting military capabilities, while Iranian media reported explosions in several cities. Iran's IRGC claimed retaliation against US assets in Kuwait and Bahrain, and attacks on oil tankers in the Strait of Hormuz. US President Trump warned of stronger responses, while Senator Schumer called for an end to the conflict.

Al Jazeera
2 min de lecture
Plus sur ce sujetmobile apps