You download an app to check your deployment schedule or rate base housing. You trust it’s safe because it’s marketed specifically to you, the military community. That trust is misplaced.
A new study reveals a grim reality. Over 12% of apps sold to US troops contain software built in China, Russia, or other adversarial nations. This isn’t just a privacy nuisance. It’s a security leak.
The code sits hidden. It can harvest data on where service members live. Where they work. When they deploy.
The Scale of the Problem
Researchers from Purdue University, West Point, and Florida International University dug into 220 military-themed apps. They pulled these from the Google Play store and private military subreddits.
The results were stark. Nearly two-thirds contained third-party Software Development Kits (SDKs). These are prebuilt code components. They handle analytics and advertising. But they also track location and user behavior.
We hope the research helps military-affiliated personnel… make more informed privacy decisions.
— Joshua Shinkle, lead author
More than one in eight apps had code linked to companies in China or Russia.
One popular app for rating living conditions included software from Huawei. US regulators flagged Huawei as a national security threat back in 2020. Other apps contained code from Russian firms. These apps integrated Yandex, a Russian ad service.
Forty percent of these apps collected or shared more data than their store listings admitted. The discrepancy between disclosure and actual practice is where the danger lives.
How Foreign SDKs Threaten Troop Safety
This isn’t theoretical. The stakes are real and immediate.
Commercial data brokers track Americans online. They don’t always distinguish between civilians and military personnel unless profit dictates it. But exposure can be deadly.
Data from ordinary apps can trace service members to:
- Their private homes
- Their children’s schools
- Off-base establishments where they are forbidden from going
Experts warn this data helps foreign spies identify personnel with access to sensitive areas. It maps when a facility is least guarded. It surfaces compromising details that can be used for recruitment, extortion, or sabotage.
In April, US Central Command confirmed what the Pentagon had suspected for years. Adversaries are already using this commercial location data to surveil US personnel in the Middle East. This includes troops stationed near the Iranian military in the Strait of Hormuz.
The Huawei HMS Core Issue
The study found HMS Core, a Huawei software kit, in twelve different apps. Some of these were built for state National Guard organizations.
HMS Core advertises the ability to:
- Map user locations
- Deliver targeted ads
- Store images and videos
No evidence suggested data was currently flowing to Huawei servers in this specific batch of apps. But an SDK can be updated remotely. Code that sits dormant today can turn into spyware tomorrow.
In one case, Huawei code entered an app without the developer’s knowledge. It was smuggled in as a dependency within a commercial notification tool. How did it get there? Probably because the developer trusted a third-party library without auditing its source.
Seventy-six different third-party code sources were found. These traced back to Israel, India, Germany, and other nations. Roughly 7% of the apps carried code from nations the Pentagon explicitly labels as adversaries.
Why Users Can’t Protect Themselves
The researchers surveyed 103 military-affiliated individuals. This included active duty, reservists, veterans, Department of Defense civilians, and their families.
The results show a systemic failure of transparency.
- 83% used at least one app with uncomfortable data practices.
- Participants used an average of three such apps.
- Between 76% and 83% were extremely uncomfortable with apps containing code from Russia, China, Iran, or North Korea.
Yet, no user has a simple way to know if their apps carry this code.
Neither the Google Play Store Data Safety section nor the Apple App Store Privacy Labels disclose the country of origin for the software running inside an app. You can see what data is collected, but you can’t see who makes the tools that collect it.
Users reported feeling more comfortable with data collection if the app was branded for military use. Branding creates trust. That trust is being exploited.
Institutional Guidance Is Missing
Nearly two-thirds of participants said they received little to no guidance on personal app use from the military. Of those who did receive guidance, nearly three-quarters called it inadequate.
The Pentagon declined to comment on the findings.
So what can be done? Participants were asked to weigh potential mitigations.
They ranked in-phone warnings as the most effective solution. Imagine an alert system that notifies you when an installed app contains foreign or unknown third-party code. Users said they would likely support this.
Other suggested measures included:
- Federal laws restricting data brokers from selling data on military personnel
- Independent audits of app privacy disclosures
- Stricter bans on foreign code in military-marketing apps
These measures drew nearly identical support from the surveyed group.
The advertising industry treats military users and civilians the same. Profit is the only differentiator. Until platforms and developers are forced to reveal the origin of the code they ship, service members will remain exposed.
The code is there. It’s just waiting for a remote update.


















