Abandoned IoT Applications Continuously Transmit Sensitive Data to Unsecured Servers

www.news4hackers.com-abandoned-iot-applications-continuously-transmit-sensitive-data-to-unsecured-servers-abandoned-iot-applications-continuously-transmit-sensitive-data-to-unsecured-servers

Millions of users continue to operate smart home and IoT companion applications that have not received updates for years, according to a study by researchers at the University of Massachusetts Amherst.

Old code, outdated servers

The research analyzed 61,500 abandoned Android IoT applications, revealing that 74% contained software dependencies linked to known vulnerabilities. The dataset was compiled from AndroZoo, a repository of Android apps, and filtered to identify companion applications for IoT devices. An app was classified as abandoned if it had not been updated for two years or had been removed from the Google Play Store by March 2025.

Many of these apps had been entirely removed from the store, while others remained listed but had not seen developer activity for years. Despite their abandonment, the apps maintained significant user bases, with thousands of installations and a dozen exceeding 100 million downloads.

According to the study, IoT devices are typically used for up to a decade, but companion applications often lack long-term maintenance. This gap forces users to rely on outdated software, increasing exposure to security risks.

Old code, outdated servers The abandoned apps frequently included software libraries with documented vulnerabilities, many of which were rated as high-severity. Researchers also identified thousands of hard-coded web addresses within the applications. Approximately 25% of the unique domains extracted from the apps were no longer functional, and every app contained at least one fully qualified domain name (FQDN) that failed DNS reachability tests.

Some of these results may stem from internal endpoints, name servers, or extraction errors, but the presence of non-resolving domains underscores the instability of the infrastructure. Abandoned applications create persistent security risks, as they cannot respond to endpoint failures. A review of domain registration histories showed that a portion of active domains had changed ownership since the apps’ last updates, affecting over 2,000 applications.

Sensitive data with nowhere safe to go

Additionally, a scan of extracted web addresses found that 11% matched threat intelligence blocklists, including phishing, scam, spyware, and malware links. Over two-thirds of the apps in the dataset contained at least one blocklisted domain.

The apps requested permissions beyond basic functionality, such as access to external storage, precise location data, and camera feeds. Researchers noted that data collected under these permissions was transmitted almost exclusively over Wi-Fi networks. A key finding was that 38.4% of unique data-flow sources and sinks were linked to domains classified as unreachable, blocklisted, or under new ownership.

According to the study, only 1% of the 500 most-installed IoT apps updated after March 2025 exhibited similar issues.

Efforts to address the problem

Researchers contacted developers of thousands of apps in the dataset via email, using available contact addresses. Nearly 20% of messages were undeliverable, while responses from the remaining recipients varied. A small number of vendors removed their apps from the Google Play Store, others denied the relevance of the flagged vulnerabilities, and a slightly larger group acknowledged the issues and stated they were working on fixes.

One vendor confirmed that a Tuya SDK vulnerability in an active app had been resolved on the cloud platform, as client-side code could not be patched directly. The study also compared the prevalence of CVE-associated dependencies between abandoned and active apps. Both groups showed similar rates of vulnerable libraries, but deprecated cryptographic practices were more common in active applications.

Meanwhile, 40.8% of unique data sinks in abandoned apps were linked to compromised or unreachable endpoints, compared to just 0.4% in the active group. The findings underscore the urgent need for improved app lifecycle management and stronger security measures for IoT ecosystems. As users continue to rely on outdated software, the risk of data exposure and exploitation remains significant.


Blog Image

About Author

en_USEnglish