Jul 21, 2026
ManyPress
Technology

Researchers found that over 12% of apps marketed to US military personnel contain software code from nations including China and Russia, raising data security concerns.

ManyPress

ManyPress

ManyPress Editorial

3 min readSource:Wired Reviewed by editors
Apps Marketed to US Military Found Containing Foreign-Origin Code

Key facts

  • Researchers analyzed over 220 apps marketed to military personnel and found that 7 percent contained code from nations the Pentagon considers adversarial.
  • Forty percent of the apps studied collected or shared more data than was disclosed in their official store listings.
  • In April, US Central Command confirmed to Senator Ron Wyden that adversaries have exploited commercial location data to target personnel in the Middle East.
  • Participants in the study ranked in-phone warnings about foreign third-party code as the most effective and supported mitigation strategy.
  • Huawei's HMS Core was found in 12 of the apps, including some developed for state National Guard organizations.

A study by researchers from Purdue University, West Point, and Florida International University found that more than one in eight mobile apps marketed to US military personnel contain software code from foreign nations, including China and Russia. The findings raise concerns that adversary governments could harvest data revealing the locations and routines of service members.

By the numbers

64%
apps containing third-party SDKs
83%
participants using apps that caused discomfort

Scope of the Research

Researchers examined over 220 apps marketed to military personnel, including banking, dating, and promotion-exam prep tools, sourced from the Google Play store and military subreddits. They found that 64 percent of these apps utilized third-party software development kits (SDKs), which are often used for analytics and advertising but can also track user behavior and location data.

Foreign Code and Data Risks

The study identified 76 different SDKs across the apps, including code originating from China, Russia, India, Israel, and Germany. Notably, 12 apps contained Huawei’s HMS Core, a software kit capable of mapping locations and storing media, with some of these apps built for state National Guard organizations. Researchers noted that while no data was observed being sent to Huawei servers, SDKs can be updated remotely, potentially turning dormant code into spyware.

User Awareness and Institutional Guidance

A survey of 103 military-affiliated individuals found that over 83 percent used at least one app with data practices that made them uncomfortable. Most participants reported receiving little or no institutional guidance regarding personal app use. Currently, neither the Google Play Store nor the Apple App Store discloses the country of origin for the software components running inside an app.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by Wired.

Technology