News by Xiaomi Miui Hellas
Home » All the news » Apps / Roms » Millions of users affected: Popular health apps leak your most personal data
Apps / Roms

Millions of users affected: Popular health apps leak your most personal data

security-alert-logo

Several mental health apps for mobile phones with millions of downloads on Google Play contain security vulnerabilities that could expose users' sensitive medical information


In fact, in one of the applications, security researchers discovered more than 85 medium and high severity vulnerabilities that could be exploited to compromise treatment data and user privacy.

Some of the products are artificial intelligence companions designed to help people suffering from clinical depression, multiple forms of anxiety, panic attacks, stress and bipolar disorder.

At least six out of ten apps analyzed state that user conversations or chats remain private or are securely encrypted on the provider's servers.

Mental health data poses unique risks. On the dark web, treatment records sold for $1.000 or more per file, much more than credit card numbers., he says Sergey Toshin, founder of the mobile security company Oversecured.

Over 1.500 security issues found

The Oversecured scanned ten mobile apps advertised as tools that can help with various mental health problems and revealed a total of 1.575 vulnerabilities security (54 with a high severity rating, 538 moderate severity and 983 low severity).

App Type installs High Medium low Total Scan date
01 Mood & habit tracker 10M + 1 147 189 337 01/23/2026
02 AI therapy chatbot 1M + 23 63 169 255 01/22/2026
03 AI emotional health platform 1M + 13 124 78 215 01/23/2026
04 Health & symptom tracker 500k + 7 31 173 211 01/22/2026
05 Depression management tool 100k + - 66 91 157 01/23/2026
06 CBT-based anxiety app 500k + 3 45 62 110 01/22/2026
07 Online therapy & support community 1M + 7 20 71 98 01/23/2026
08 Anxiety & phobia self-help 50k + - 15 54 69 01/22/2026
09 Military stress management 50k + - 12 50 62 01/22/2026
10 AI CBT chatbot 500k + - 15 46 61 01/23/2026

While none of the issues discovered are critical, many can be exploited to steal login credentials, fake notifications, HTML injection or to identify the user.

The researchers used the Oversecured scanner to check the APK files of ten mental health apps for known vulnerability patterns across dozens of categories.

In a report shared with the BleepingComputer, the researchers say that some of the verified apps "parse user-provided URIs without sufficient validation."

A treatment application with more than one million downloads uses it Intent.parseUri() to an externally controlled string and initiates the resulting messaging object (intent) without validating the target element.

This allows an attacker to force the application to open any internal activity, even if it is not intended for external access.

Since these internal activities often handle authentication tokens and session data, the exploit could give an attacker access to a user's treatment records., explains the Oversecured.

Another issue is storing data locally in a way that provides read access to any app on the device. Depending on the information stored, this could expose treatment details, such as treatment records, Cognitive Behavioral Therapy (CBT) session notes, etc.CBT) and various ratings.

Η Oversecured states that they also discovered plain text configuration data, including support API endpoints and a database URL Firebase with embedded code, within the application resources (APK).

Additionally, some of the vulnerable applications use insecure class cryptography. java.util.Random to generate session tokens or encryption keys.

According to the researchers, most of the 10 apps lack any form of root detection. On a rooted device (jailbroken), any app with root privileges has access to all health data stored locally.

Η Oversecured says that six out of the ten applications analyzed "had zero high-severity findings, but still had medium-severity issues that weakened their overall security posture».

These apps collect and store some of the most sensitive personal data on mobile: therapy session transcripts, mood logs, medication schedules, self-harm indicators, and in some cases, HIPAA-protected information., the researchers note.

From his observations BleepingComputer, the collective number of downloads for the apps scanned by Oversecured is over 14.7 million and only four were updated just this month. For the rest, the last update date was as recent as November 2025 or even September 2024.

His scans Oversecured took place between January 22 and 23 and targeted the latest versions of applications available at the time. Researchers cannot confirm whether any of the uncovered vulnerabilities have been addressed.

The BleepingComputer declined to disclose the names of the affected applications, as the vulnerabilities are still being disclosed by the Oversecured.


Mi TeamDo not forget to follow it Xiaomi-miui.gr on Google News to be informed immediately about all our new articles! You can also if you use RSS reader, add our page to your list by simply following this link >> https://xiaomi-miui.gr/feed

 

Follow us on Telegram so you can be the first to hear about our news! (English version HERE)

Read also

Get Avalar: Raid of Shadow Premium along with 32 additional games and apps from the Google Play Store

Mi Team

Get Water Sort Puzzle – Premium along with 72 additional games and apps from the Google Play Store

Mi Team

Get Defense Zone HD along with 45 additional games and apps from the Google Play Store

Mi Team

Get Avalar: Shadow War Premium along with 42 additional games and apps from the Google Play Store

Mi Team

Get Theme Park Simulator along with 36 additional games and apps from the Google Play Store

Mi Team

Get Live or Die 1: Survival Pro along with 26 additional games and apps from the Google Play Store

Mi Team

Leave a comment

* By using this form you agree to the storage and distribution of your messages on our page.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Leave a Review

Xiaomi Miui Hellas
The official community of Xiaomi, MIUI and HyperOS in Greece.