
Two Android apps owned by Chinese tech company Baidu have been removed from the official Google StorePlay after they were found to be collecting sensitive user.
The apps in question are Baidu Maps and Baidu Search Box , and they were removed after Google received a report from US security firm Palo Alto Networks. They are two very popular apps with millions of downloads.
According to the security firm, the two apps contained code designed to collect information about the user's phone model, MAC address, carrier information , and IMSI code (International Mobile Subscriber Identity)
Specifically, the code was found in the Baidu Push SDK, which is used to display notifications (in real time) in both applications.
Palo Alto Networks security researchers Stefan Achleitner and Chengcheng Xu discovered the code that collects data. Some of the data collected is harmless, but there is also other data, such as the IMSI code, which “can be used to identify and track a user, even if that user uses a different phone.”
Google doesn't actually prohibit Android apps from collecting user data. However, the Play Store's security team reviewed Palo Alto Networks' report, confirmed its findings, and "identified [additional] violations" in the two Baidu apps. For this reason, they were removed from the Play Store in late October.
The Baidu Search Box app is back in the Play Store, but Palo Alto Networks said Baidu developers have removed the data.

However, security researchers noticed that it's not just the Baidu Push SDK that's collecting user. They also discovered another piece of code in ShareSDK, created by Chinese company MobTech.
This SDK is used in more than 37,500 apps, and according to the researchers, it collects data such as phone model information, screen resolution, MAC addresses, Android ID, Advertising ID, carrier information, and IMSI (International Mobile Subscriber Identity) and IMEI (International Mobile Equipment Identity) codes.
“analysis malware shows that SDKs, such as Baidu Push SDK or ShareSDK, are frequently used in malicious apps to extract and transfer device data,” Achleitner and Xu said, emphasizing that the two SDKs have been developed for legitimate purposes (e.g., pushing notifications and sharing content on social media), but are often used by malicious app developers.
Source: ZDNet
