Abandoned IoT apps keep sending sensitive data to broken servers
Researchers at UMass Amherst analyzed 61,500 abandoned Android smart home apps: nearly three in four have dependencies with known vulnerabilities, and 40.8% of data transmission points lead to unreachable or dangerous domains.
- 73.6% of abandoned apps contain dependencies with CVEs
- 40.8% of data transmission points lead to dead or dangerous domains
- For active apps, that share is only 0.4%
- 12 apps had over 100 million downloads before being abandoned
Read next
Security