Eight Android and iOS applications are putting user data at serious risk by failing to properly secure sensitive information. These apps transmit crucial data—such as device details, geolocation, and user credentials—over the unsecured HTTP protocol instead of the more secure HTTPS, leaving the data vulnerable to various forms of cyberattacks, including data theft, eavesdropping, and man-in-the-middle attacks. The lack of proper encryption is a critical flaw in these apps, reflecting poor security practices by their developers.
The list of apps with these vulnerabilities includes:
- Klara Weather (Android)
- Military Dating App – MD Date (iOS)
- Sina Finance (Android)
- CP Plus Intelli Serve (Android)
- Latvijas Pasts (Android)
- HaloVPN: Fast Secure VPN Proxy (iOS)
- i-Boating: Marine Charts & GPS (iOS)
- Texas Storm Chasers (iOS)
Klara Weather and Military Dating apps are particularly concerning, as they transmit data without encryption. Klara Weather leaks users’ geolocation information over HTTP, compromising their privacy. The Military Dating app goes a step further by sending usernames and passwords without encryption, making it easy for attackers to intercept and misuse this sensitive information. This could lead to unauthorized access to personal accounts, identity theft, and other malicious activities.

Similarly, the Android apps Sina Finance and CP Plus Intelli Serve pose significant risks by leaking device-specific information, such as device IDs, SDK versions, and IMEI numbers, over unsecured connections. CP Plus Intelli Serve also transmits usernames and passwords in plain text, offering attackers an easy path to steal these credentials. The failure to use HTTPS encryption in these apps leaves users highly susceptible to privacy breaches.

The apps Latvijas Pasts and HaloVPN, despite their popularity with over 100,000 and 13,300 downloads respectively, are also found to be transmitting sensitive data unencrypted. Analyzing their network traffic revealed that Latvijas Pasts leaks geolocation data, while HaloVPN exposes device details, including the device ID, language, model, name, time zone, and SIM information, all over HTTP.

Finally, i-Boating: Marine Charts & GPS and Texas Storm Chasers continue this trend of poor security, with i-Boating transmitting device type and OS version, and Texas Storm Chasers sending geolocation data over unsecured connections. These lapses expose users to significant risks, including eavesdropping and data interception by malicious actors.

The recurring issue of transmitting unencrypted data in mobile apps underscores the urgent need for developers to prioritize security. Implementing HTTPS for all network traffic, encrypting sensitive information, performing regular security audits, and maintaining a vigilant approach to user data protection are essential steps to safeguard user privacy.
To mitigate the risks, Symantec recommends that users protect their mobile devices by installing trusted security apps, avoiding downloads from unverified sources, keeping software up to date, carefully reviewing app permissions, and regularly backing up important data. These measures can significantly reduce the chances of a mobile device being compromised.



