Security News > 2023 > February > Even Top-Ranked Android Apps in Google Play Store Provide Misleading Data Safety Labels

An investigation into data safety labels for Android apps available on the Google Play Store has uncovered "Serious loopholes" that allow apps to provide misleading or outright false information.
The study, conducted by the Mozilla Foundation as part of its *Privacy Not Included initiative, compared the privacy policies and labels of the 20 most popular paid apps and the 20 most popular free apps on the app marketplace.
It found that, in roughly 80% of the apps reviewed, "The labels were false or misleading based on discrepancies between the apps' privacy policies and the information apps self-reported on Google's Data safety form."
Last year, Google began rolling out a new Data safety section on the Play Store that spells out the apps' privacy and security practices.
Google exempts apps sharing data with 'service providers' from its disclosure requirements, which is problematic due to both the narrow definition it uses for service providers and the large amount of consumer data involved," Mozilla said.
It's worth pointing out here that apps can be exempted from disclosing data sharing provided they have sought users' consent, if the data is being shared with a developer's service provider, or if the data is fully anonymized.
News URL
https://thehackernews.com/2023/02/majority-of-android-apps-on-google-play.html
Related news
- Google blocked 2.36 million risky Android apps from Play Store in 2024 (source)
- Crypto-stealing iOS, Android malware found on App Store, Google Play (source)
- SpyLend Android malware downloaded 100,000 times from Google Play (source)
- Google Bans 158,000 Malicious Android App Developer Accounts in 2024 (source)
- Google fixes Android kernel zero-day exploited in attacks (source)
- Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024-53104 (source)
- Google patches odd Android kernel security bug amid signs of targeted exploitation (source)
- Google Play, Apple App Store apps caught stealing crypto wallets (source)
- Week in review: Exploited 7-Zip 0-day flaw, crypto-stealing malware found on App Store, Google Play (source)
- Google Confirms Android SafetyCore Enables AI-Powered On-Device Content Classification (source)