A number of psychological well being cellular apps with thousands and thousands of downloads on Google Play include safety vulnerabilities that would expose customers’ delicate medical data.
In one of many apps, safety researchers found greater than 85 medium- and high-severity vulnerabilities that may very well be exploited to compromise customers’ remedy knowledge and privateness.
A number of the merchandise are AI companions designed to assist folks affected by scientific melancholy, a number of types of anxiousness, panic assaults, stress, and bipolar dysfunction.

Not less than six of the ten analyzed apps state that consumer conversations or chats stay personal, or are encrypted securely on the seller’s servers.
“Mental health data carries unique risks. On the dark web, therapy records sell for $1,000 or more per record, far more than credit card numbers,” says Sergey Toshin, founding father of cellular safety firm Oversecured.
Over 1,500 safety points discovered
Oversecured scanned ten cellular apps marketed as instruments that may assist with numerous psychological well being issues, and uncovered a complete of 1,575 safety vulnerabilities (54 rated high-severity, 538 medium-severity, and 983 low-severity).
| App Kind | Installs | Excessive | Medium | Low | Whole | Scan date | |
| 01 | Temper & behavior tracker | 10M+ | 1 | 147 | 189 | 337 | 01/23/2026 |
| 02 | AI remedy chatbot | 1M+ | 23 | 63 | 169 | 255 | 01/22/2026 |
| 03 | AI emotional well being platform | 1M+ | 13 | 124 | 78 | 215 | 01/23/2026 |
| 04 | Well being & symptom tracker | 500k+ | 7 | 31 | 173 | 211 | 01/22/2026 |
| 05 | Despair administration device | 100k+ | – | 66 | 91 | 157 | 01/23/2026 |
| 06 | CBT-based anxiousness app | 500k+ | 3 | 45 | 62 | 110 | 01/22/2026 |
| 07 | On-line remedy & assist neighborhood | 1M+ | 7 | 20 | 71 | 98 | 01/23/2026 |
| 08 | Anxiousness & phobia self-help | 50k+ | – | 15 | 54 | 69 | 01/22/2026 |
| 09 | Army stress administration | 50k+ | – | 12 | 50 | 62 | 01/22/2026 |
| 10 | AI CBT chatbot | 500k+ | – | 15 | 46 | 61 | 01/23/2026 |
Though not one of the found points are vital, many might be leveraged to intercept login credentials, spoof notifications, HTML injection, or to find the consumer.
The researchers used the Oversecured scanner to test the APK recordsdata of the ten psychological well being purposes for recognized vulnerability patterns in dozens of classes.
In a report shared with BleepingComputer, the researchers say that a few of the verified apps “parse user-supplied URIs without adequate validation.”
One remedy app with multiple million downloads makes use of Intent.parseUri() on an externally managed string and launches the ensuing messaging object (intent) with out validating the goal element.
This enables an attacker to drive the app to open any inside exercise, even when it isn’t supposed for exterior entry.
“Since these internal activities often handle authentication tokens and session data, exploitation could give an attacker access to a user’s therapy records,” Oversecured explains.
One other challenge is storing knowledge domestically in a method that offers learn entry to any app on the system. Relying on the saved data, this might expose remedy particulars, comparable to remedy entries, Cognitive Behavioral Remedy (CBT) session notes, and numerous scores.
Oversecured states that in addition they found plaintext configuration knowledge, together with backend API endpoints and a hardcoded Firebase database URL, inside the APK assets.
Moreover, a few of the susceptible apps use the cryptographically insecure java.util.Random class for producing session tokens or encryption keys.
In keeping with the researchers, “most of the 10 apps lack any form of root detection.” On a rooted (jailbroken) system, any app with root privileges has entry to all well being knowledge saved domestically.
Oversecured says that six of the ten analyzed apps “had zero high-severity findings, but still carried medium-severity issues that weaken their overall security posture.”
“These apps collect and store some of the most sensitive personal data in mobile: therapy session transcripts, mood logs, medication schedules, self-harm indicators, and in some cases, information protected under HIPAA,” the researchers observe.
From BleepingComputer’s observations the collective obtain depend for the apps scanned by Oversecured is greater than 14.7 million, and solely 4 obtained an replace as lately as this month. For the remaining, the date of the newest replace was as current as November 2025 and even September 2024.
Oversecured’s scans occurred between January 22 and 23 and focused the newest app variations obtainable on the time. The researchers can’t verify if any of the uncovered vulnerabilities have been addressed.
BleepingComputer has kept away from the sharing the names of the impacted apps because the vulnerabilities are nonetheless being disclosed by Oversecured.

Trendy IT infrastructure strikes quicker than handbook workflows can deal with.
On this new Tines information, find out how your crew can cut back hidden handbook delays, enhance reliability by means of automated response, and construct and scale clever workflows on prime of instruments you already use.



