By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about
News

DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about

News Room
Last updated: 2025/02/11 at 2:22 PM
News Room Published 11 February 2025
Share
SHARE

Tech fans who flocked to try out DeepSeek will want to think twice about what the app is doing – just days after vulnerabilities were found in the iOS app, a research team at Security Scorecard has found similar privacy concerns in the Android app as well.

Despite the app’s rise in popularity after the release of the R1 reasoning model, several countries including Australia, Italy and Taiwan have banned it from use in government departments or on government devices amid privacy concerns. While the latest report from Security Scorecard doesn’t show any overtly malicious behavior, it does point to some overall poor security practices.

The concerns include sending user data to China, hardcoded keys, weak cryptography, and vulnerabilities to SQL injection attacks among others. Additionally, the report says that API keys, authentication tokens and passwords are stored in plaintext within application files which increases risks of unauthorized access and account takeover.

The app’s privacy policy details additional risky behavior such as collecting “text or audio inputs, prompts, uploaded files, feedback and chat history.” It also gathers technical information like IP addresses, operating system, device model and – most concerningly – “keystroke patterns or rhythms.” This last part is considered most intrusive as it can be used to infer both identity and behavior.

Security Scorecard analyzed the app and identified these issues based on the CWE (Common Weakness Enumeration) list. High risk weaknesses include things like hardcoded keys, SQL injection risks, improper file permissions, while analysis of DeepSeek’s Smali code revealed multiple anti-debugging techniques. If debugging is detected; the application force closes itself to prevent analysis.

The report also examines the likelihood of user behavior and device metadata being sent to ByteDance servers which would raise compliance issues with GDPR, CCPA and national security laws.

If you’re thinking about using Deepseek as your new AI tool, this report’s findings are more than enough reason to reconsider. Hopefully, its creators are able to fix some of these security issues soon before hackers, governments or other threat actors figure out how to exploit them.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

More from Tom’s Guide

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Hit The Snooze on Cache Keys and How It Boosts Web App Performance | HackerNoon
Next Article Apple Arcade Is Getting the Rhythm Game Piano Tiles 2 and More Soon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

new gameplay trailer, release date, price, everything is there
Mobile
Womp, womp: Tesla kills the $16,000 Cybertruck Range Extender
News
BYD said to be launching cheaper Qin electric sedan amid price war · TechNode
Computing
Microsoft Office 2019 is on Sale for a $ 46 – Pay Once and Use It Forever
Software

You Might also Like

News

Womp, womp: Tesla kills the $16,000 Cybertruck Range Extender

3 Min Read

World Video Game Hall of Fame inducts Defender, Tamagotchi, GoldenEye 007 and Quake

4 Min Read
News

How Google’s new Gemini AI update keeps us safe from online scams

4 Min Read
News

Most AI Spending Due to Fear of Falling Behind, According to IBM

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?