Free Android VPNs Are Leaking Your Traffic, Study of 281 Apps Finds
Researchers tested the most popular free VPN apps on Google Play. A significant share fail at the one job they promise: keeping your internet activity private.

Key points
- Researchers tested 281 of the most-installed free VPN apps on Google Play and found widespread privacy failures.
- The flagged apps have been installed more than 2.4 billion times between them.
- 29 apps allowed user traffic to leak outside the encrypted tunnel entirely.
- The problems are basic misconfigurations, not sophisticated attacks, and they undermine the core reason people install a VPN.
A new study of free Android VPN apps has found that many of the most popular ones fail at the basic job they advertise: hide your internet traffic from anyone watching and keep it encrypted end to end.
A VPN, short for virtual private network, routes your phone's internet activity through a secure tunnel so your internet provider or the operator of a public Wi-Fi network can't see what you're doing. People install them for privacy, for streaming, and for getting around censorship.
Researchers ran 281 of the most-downloaded free VPN apps on Google Play through an automated testing system. The findings, first reported by The Hacker News, aren't pretty. We've tracked Android security failures at the platform level since early June, including a debug flag that exposed Microsoft 365 tokens to any sideloaded app on the same device; what this study adds is evidence the threat layer extends to apps users actively choose for protection.
Should you stop using your free VPN?
If it's on the flagged list, yes, at least until the developer fixes it. The apps that failed have been installed a combined 2.4 billion times, which gives a sense of how many phones are affected.
These aren't exotic failures. They're the kind of mistakes a competent developer should catch before shipping.
29 of the apps let user traffic leak outside the encrypted tunnel altogether, meaning the activity the app promised to hide was travelling in the clear, visible to an internet provider or anyone monitoring a shared network. Other apps sent data without proper encryption or bundled tracking code that quietly reported user activity to third parties. Some of these VPNs were doing the opposite of what their users installed them to do.
Why free VPNs so often fail
Running a VPN service costs real money. Servers, bandwidth and engineering staff aren't free. If the user isn't paying, something else funds the operation.
That something is usually advertising or data collection. Free VPN apps have a long history of embedding tracking libraries, selling aggregated browsing data, or cutting corners on encryption to save on server costs.
Academic studies going back years have found that a large share of free Android VPNs contain tracking code or ship with weak encryption. This study confirms the pattern hasn't gone away.
What ordinary users should do
A few practical steps, no panic required.
First, check whether your VPN app is one of the flagged ones when the researchers publish the full list. If it is, uninstall it.
Second, be sceptical of any VPN that's completely free with no paid tier. A reputable provider will have a clear business model that doesn't depend on your data.
Third, remember that a VPN isn't a magic shield. It hides your traffic from the network you're on, but it won't stop phishing or malware, and it can't undo permissions you've already granted a shady app.
If you genuinely need a VPN for privacy, a paid service from a provider with a published independent audit is a safer bet than a free app you found by searching the Play Store.
Google hasn't said whether it will remove the flagged apps. Play Store policy does require apps using the VPN service to be transparent about data handling, and repeated academic findings like this one tend to prompt at least some enforcement action.



