Security researchers have discovered critical vulnerabilities in top VPN apps offered for free for Android devices . The vulnerabilities allow attackers to perform Man-in-the-Middle attacks and steal sensitive user data

There are many dangerous VPN apps that have been installed on more than 120 million devices. The free VPN, called SuperVPN, has been installed on at least 100 million Android devices.
This particular VPN application is used by users in 150 countries.
SuperVPN is designed by SuperSoftTech, a company based in Singapore. However, it is actually owned by independent app publisher Jinrong Zheng, from China.
Unencrypted communications
Security researchers examined SuperVPN and found that sensitive encrypted data over insecure HTTP.
Also, the VPN application contains a decryption key that allowed researchers to decrypt the data.
This leads to the discovery of sensitive data about the server , its certificates, and the credentials that the VPN server needs for authentication.
Attackers can use this information and replace the real SuperVPN server data with fake server data.
The severity of vulnerabilities
According to experts, attackers can exploit vulnerabilities in VPNs and monitor users' communications and activities . In this way, they can gain access to sensitive data, such as the sites users visit . In addition, they can steal usernames and passwords, photos, videos, messages and more.

According to the researchers, “some applications have their encryption keys inside the VPN application. This means that even if the data is encrypted, hackers can easily decrypt using these keys.”
Developers of VPN applications left some of the keys behind, helping attackers gain easy access to users' encrypted data.
“In 2016, SuperVPN had only 10,000 downloads. Now, it has more than 100 million. Even though many articles said that SuperVPN was malicious, it has not yet been removed from the Play Store,” the researchers said.
