HomeSecurityAndroid Keyboard App Secretly Collects Your Data

Android Keyboard App Secretly Collects Your Data

Google has removed one of the top 20 most popular Android apps from the Play Store after an investigation by Pentest, a UK-based cybersecurity firm, found that a keyboard app violated Google's policies by displaying deceptive behavior.

Pentest engineers found that the app requested more permissions than it needed. It requested administrator privileges to make uninstallation, hijacked the user's screen to display ads, and collected and transferred user information to third parties without the user's permission.

Android Keyboard App Secretly Collects Your Data

The app is called Flash Keyboard and before the Pentest report , it was ranked 11th on Google 's most popular Android apps , with over 50 million downloads. As its name suggests, the app is a replacement for the stock Android keyboard, developed by DOTC United.

Pentest found it excessive that the app required access to Bluetooth connection, geolocation capability, or WiFi status.

Additionally, the app requested access to kill background processes, read SMS messages, show system overlays, or remove download notifications. Pentest says there is no reason for a keyboard app to require these intrusive permissions.

Additionally, Pentest discovered that the Flash keyboard requested device administration permissions and used them to display ads even over a locked screen.

ads over locked screen

Pentest also analyzed a data stream coming from the app and says that the Flash keyboard was collecting user information and sending it to remote servers in the US, the Netherlands, and China.

Some of the data the app collected and sent to these services included details such as the device manufacturer, device model number, Android version, email address, SSID, MAC, IMEI, mobile network, GPS coordinates, information about nearby Bluetooth devices, and the presence of any proxies.

Pentest believes that the app violates Google's deceptive behavior policy for the following reasons:

  • “It mimics the functionality of the operating system by replacing the built-in lock screen with its own.”
  • “It doesn't inform that it overrides the lock screen to display ads.”
  • “It allows app updates and intentionally hides operating system notifications that alert the user to perform updates.”
  • “Sends personal information to third-party sources, without the user’s knowledge.”
  • “It makes it difficult for the average user to uninstall it.”

Following the Pentest report, Google removed the app. Shortly thereafter, the developer created and submitted an app called Flash Keyboard – Lite to the Play Store . At the time of writing, Flash Keyboard is once again available through the Google Play Store

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS