Free Android VPN Apps May Be Putting Your Privacy at Risk, New Research Warns
A VPN is often marketed as a simple way to protect your privacy online. It creates an encrypted tunnel between your device and the internet, making it harder for your internet provider, public Wi-Fi operators, or nearby snoopers to see what you are doing.
But there is an important trade-off many users forget: once you connect to a VPN, you are trusting the VPN provider with your internet traffic. Instead of your internet service provider seeing your activity, the VPN company may be able to see it. That makes the reliability and security of the VPN app extremely important.
A new academic study suggests that many free Android VPN apps fail that trust test.
Researchers from the University of Michigan, the University of New Mexico, and IIT Delhi examined 281 free VPN apps available on the Google Play Store using Android 14 devices. Their testing framework, called MVPNalyzer, was presented at the NDSS security conference, and the University of Michigan published the findings in July.
The results are worrying. Apps with at least one identified issue were installed more than 2.4 billion times in total, showing just how widespread the problem may be for Android users.
Some VPN apps could be hijacked on public Wi-Fi
One of the most serious issues involved five VPN apps that downloaded their configuration files without encryption. These configuration files tell the VPN app which server to connect to.
If that file is sent in plain text, an attacker on the same Wi-Fi network could intercept and modify it. For example, someone controlling a public hotspot in a café, airport, hotel, or shopping center could redirect the VPN connection to a server they control.
To the user, everything may look normal. The app still shows a “Connected” message, creating the impression that the VPN is protecting the connection. In reality, the user’s traffic could be passing through an attacker’s server.
The researchers successfully reproduced this attack on their own test devices. Out of the five providers affected, two responded and said they would move to HTTPS for configuration delivery. Three did not respond.
Many free VPNs leaked data outside the secure tunnel
A VPN should prevent your traffic from escaping outside the encrypted connection. However, the study found that 29 apps allowed some form of data leakage.
In 24 cases, the apps leaked DNS queries. DNS queries reveal which websites a user is trying to visit, even if the actual page content remains encrypted. These 24 apps alone had around 360 million installations, making the issue highly significant.
The study also found that six apps leaked all traffic, while four created VPN tunnels without any encryption at all. That means users may have believed they were protected when they were not receiving meaningful protection.
For people using free VPN apps on public Wi-Fi, this is especially concerning. Many users install a VPN specifically to prevent data exposure on untrusted networks, but some of these apps may provide little or no real privacy.
Tracking remains a major concern
VPN users often want to reduce tracking, but the study found that many free Android VPNs include tracking behavior of their own.
According to the researchers, 76 apps transmitted the device’s advertising ID. This identifier can be used by advertisers and data brokers to follow users across different apps and services.
Even more concerning, 246 apps, more than 80 percent of those tested, contacted known advertising or tracking servers. These apps shared details such as the device model, Android version, and screen size.
Individually, those details may seem harmless. Combined, they can help create a unique device fingerprint, making it easier to identify and track a user over time. One app even transmitted exact GPS coordinates, raising serious privacy concerns.
This creates a contradiction: some free VPNs advertise themselves as privacy tools while collecting or sharing data that can be used for tracking.
Outdated encryption puts users at further risk
The researchers also reviewed OpenVPN configuration files used by 108 of the tested apps. Only one app met all the security requirements examined in the study.
About 89 percent relied on only one authentication method instead of combining stronger methods such as passwords and certificates. Nearly one in five used weak or outdated encryption, including Blowfish and Triple DES, both of which are considered unsuitable for modern security needs.
Some apps disabled encryption inside the VPN tunnel entirely.
The broader issue appears to be poor maintenance. Many free VPN apps may not receive the updates, security reviews, or careful engineering needed to protect users properly. The study also questioned the value of “verified” labels for VPN apps, suggesting that such badges should not be treated as a guarantee of strong privacy or security.
This is not the first warning about free VPN apps
The new findings add to a growing list of concerns about free VPN services.
In August 2025, researchers from Citizen Lab and Arizona State University found several popular Android VPN apps with more than 700 million combined downloads that appeared to be secretly connected to one another. Some shared hard-coded passwords and collected location data.
In October 2025, security researchers reported that several free VPNs were still using a version of OpenSSL vulnerable to Heartbleed, a serious flaw that was patched back in 2014.
Together, these findings suggest that the problem is not limited to a few careless apps. Free VPN services can carry hidden risks, especially when users cannot easily inspect what the app is doing behind the scenes.
How to choose a safer VPN app
The hardest part for ordinary users is that many of the most dangerous flaws are invisible. You cannot easily tell whether a VPN app is using weak encryption, leaking DNS requests, or loading configuration files insecurely just by looking at its interface.
That means choosing a VPN should be less about flashy promises and more about trust.
Look for providers that publish recent independent security audits. A serious VPN company should be willing to let outside experts examine its systems and apps.
Be cautious with free VPN apps that rely heavily on ads. If you are not paying with money, the business model may depend on advertising, tracking, or data collection.
Do not treat claims such as “no logs,” “military-grade encryption,” or “verified” as proof. These phrases are often used in marketing and may not reflect real-world security.
Check whether the provider clearly explains who owns the service, where it operates, what data it collects, and how it protects user traffic. A lack of transparency is a warning sign.
The bottom line
A VPN can be useful, especially on public Wi-Fi or when you want to reduce exposure to your internet provider. But not every VPN improves your privacy. Some free Android VPN apps may leak your browsing activity, track your device, use outdated encryption, or even expose your traffic to attackers.
The safest approach is to treat VPN apps as highly sensitive software. You are trusting them with your internet connection, so the company behind the app matters as much as the technology it claims to use.
For Android users, the message is clear: a free VPN may look convenient, but if it is poorly built or funded by aggressive tracking, it could offer less protection than you think.






