Researchers found that over 12% of apps marketed to US military personnel contain software code from nations including China and Russia, raising data security concerns.

Key facts
- •Researchers analyzed over 220 apps marketed to military personnel and found that 7 percent contained code from nations the Pentagon considers adversarial.
- •Forty percent of the apps studied collected or shared more data than was disclosed in their official store listings.
- •In April, US Central Command confirmed to Senator Ron Wyden that adversaries have exploited commercial location data to target personnel in the Middle East.
- •Participants in the study ranked in-phone warnings about foreign third-party code as the most effective and supported mitigation strategy.
- •Huawei's HMS Core was found in 12 of the apps, including some developed for state National Guard organizations.
A study by researchers from Purdue University, West Point, and Florida International University found that more than one in eight mobile apps marketed to US military personnel contain software code from foreign nations, including China and Russia. The findings raise concerns that adversary governments could harvest data revealing the locations and routines of service members.
By the numbers
Scope of the Research
Researchers examined over 220 apps marketed to military personnel, including banking, dating, and promotion-exam prep tools, sourced from the Google Play store and military subreddits. They found that 64 percent of these apps utilized third-party software development kits (SDKs), which are often used for analytics and advertising but can also track user behavior and location data.
Foreign Code and Data Risks
The study identified 76 different SDKs across the apps, including code originating from China, Russia, India, Israel, and Germany. Notably, 12 apps contained Huawei’s HMS Core, a software kit capable of mapping locations and storing media, with some of these apps built for state National Guard organizations. Researchers noted that while no data was observed being sent to Huawei servers, SDKs can be updated remotely, potentially turning dormant code into spyware.
User Awareness and Institutional Guidance
A survey of 103 military-affiliated individuals found that over 83 percent used at least one app with data practices that made them uncomfortable. Most participants reported receiving little or no institutional guidance regarding personal app use. Currently, neither the Google Play Store nor the Apple App Store discloses the country of origin for the software components running inside an app.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by Wired.

