
A number of psychological well being cellular apps with hundreds of thousands of downloads on Google Play include safety vulnerabilities that would expose customers’ delicate medical info.
In one of many apps, safety researchers found greater than 85 medium- and high-severity vulnerabilities that could possibly be exploited to compromise customers’ remedy knowledge and privateness.
A number of the merchandise are AI companions designed to assist individuals affected by medical melancholy, a number of types of nervousness, panic assaults, stress, and bipolar dysfunction.
No less than six of the ten analyzed apps state that person conversations or chats stay personal, or are encrypted securely on the seller’s servers.
“Psychological well being knowledge carries distinctive dangers. On the darkish net, remedy data promote for $1,000 or extra per file, excess of bank card numbers,” says Sergey Toshin, founding father of cellular safety firm Oversecured.
Over 1,500 safety points discovered
Oversecured scanned ten cellular apps marketed as instruments that may assist with varied psychological well being issues, and uncovered a complete of 1,575 safety vulnerabilities (54 rated high-severity, 538 medium-severity, and 983 low-severity).
| App Kind | Installs | Excessive | Medium | Low | Complete | Scan date | |
| 01 | Temper & behavior tracker | 10M+ | 1 | 147 | 189 | 337 | 01/23/2026 |
| 02 | AI remedy chatbot | 1M+ | 23 | 63 | 169 | 255 | 01/22/2026 |
| 03 | AI emotional well being platform | 1M+ | 13 | 124 | 78 | 215 | 01/23/2026 |
| 04 | Well being & symptom tracker | 500k+ | 7 | 31 | 173 | 211 | 01/22/2026 |
| 05 | Despair administration instrument | 100k+ | – | 66 | 91 | 157 | 01/23/2026 |
| 06 | CBT-based nervousness app | 500k+ | 3 | 45 | 62 | 110 | 01/22/2026 |
| 07 | On-line remedy & help neighborhood | 1M+ | 7 | 20 | 71 | 98 | 01/23/2026 |
| 08 | Nervousness & phobia self-help | 50k+ | – | 15 | 54 | 69 | 01/22/2026 |
| 09 | Army stress administration | 50k+ | – | 12 | 50 | 62 | 01/22/2026 |
| 10 | AI CBT chatbot | 500k+ | – | 15 | 46 | 61 | 01/23/2026 |
Though not one of the found points are important, many may be leveraged to intercept login credentials, spoof notifications, HTML injection, or to find the person.
The researchers used the Oversecured scanner to examine the APK recordsdata of the ten psychological well being functions for recognized vulnerability patterns in dozens of classes.
In a report shared with BleepingComputer, the researchers say that a number of the verified apps “parse user-supplied URIs with out sufficient validation.”
One remedy app with multiple million downloads makes use of Intent.parseUri() on an externally managed string and launches the ensuing messaging object (intent) with out validating the goal element.
This permits an attacker to pressure the app to open any inside exercise, even when it’s not meant for exterior entry.
“Since these inside actions usually deal with authentication tokens and session knowledge, exploitation may give an attacker entry to a person’s remedy data,” Oversecured explains.
One other situation is storing knowledge domestically in a approach that provides learn entry to any app on the machine. Relying on the saved info, this might expose remedy particulars, equivalent to remedy entries, Cognitive Behavioral Remedy (CBT) session notes, and varied scores.
Oversecured states that in addition they found plaintext configuration knowledge, together with backend API endpoints and a hardcoded Firebase database URL, throughout the APK assets.
Moreover, a number of the weak apps use the cryptographically insecure java.util.Random class for producing session tokens or encryption keys.
In accordance with the researchers, “a lot of the 10 apps lack any type of root detection.” On a rooted (jailbroken) machine, any app with root privileges has entry to all well being knowledge saved domestically.
Oversecured says that six of the ten analyzed apps “had zero high-severity findings, however nonetheless carried medium-severity points that weaken their total safety posture.”
“These apps gather and retailer a number of the most delicate private knowledge in cellular: remedy session transcripts, temper logs, medicine schedules, self-harm indicators, and in some instances, info protected beneath HIPAA,” the researchers word.
From BleepingComputer’s observations the collective obtain depend for the apps scanned by Oversecured is greater than 14.7 million, and solely 4 obtained an replace as just lately as this month. For the remaining, the date of the newest replace was as current as November 2025 and even September 2024.
Oversecured’s scans occurred between January 22 and 23 and focused the newest app variations obtainable on the time. The researchers can’t verify if any of the uncovered vulnerabilities have been addressed.
BleepingComputer has avoided the sharing the names of the impacted apps because the vulnerabilities are nonetheless being disclosed by Oversecured.


