Thousands of Android and Samsung Pre-Installed Apps Come With Hidden Backdoors, Study Claims

A total of 150,000 apps have been analysed using a tool called InputScope. Out of these, 12,706 apps were found to have presence of backdoors.

Advertisement
By Tasneem Akolawala | Updated: 8 April 2020 13:03 IST
Highlights
  • 4,028 tested apps seem to be checking for blacklisted words
  • Researchers scanned 150,000 apps using a tool called InputScope
  • 4.5 percent of apps from Baidu indulged in blacklisting

Study shows pre-installed apps come with more unethical backdoors behaviour than other apps

A new study claims that thousands of Android apps may come with input-triggered secrets such as backdoors and blacklists of unwanted items. A total of 150,000 apps have been analysed using a newly developed tool called InputScope. Out of these, 12,706 apps were found to have presence of backdoors, and over 4,028 apps seem to be checking for blacklisted words. From the 150,000 apps, 100,000 apps were from Google Play Store and 30,000 apps were pre-installed ones on Samsung phones.

The new study comes from researchers at Ohio State University, New York University, and the Helmholtz Center for Information Security (CISPA). These researchers analysed these 150,000 apps using an analysis tool called InputScope. This tool helped in automatic detection of both the execution context of user input validation and the content involved in the validation to automatically expose hidden functionality. As mentioned, the pool of apps had Android apps from Google Play Store, pre-installed apps from Samsung phones, and 20,000 apps from Chinese market Baidu as well.

The test uncovered 12,706 mobile apps containing backdoor secrets and 4,028 mobile apps containing blacklist secrets. Undocumented backdoors include secret access keys, master passwords, and secret privileged commands, and blacklists of unwanted items include censorship keywords, cyber-bulling expressions, and weak passwords.

Advertisement

The study also showed that pre-installed apps showed more unethical backdoors behaviours than other apps. The percentage of undocumented backdoor instances on pre-installed apps was around 16 percent, while Google Play Store apps were at 6.8 percent. Baidu apps were at 5.3 percent – the least of the lot. For blacklisting, 4.5 percent of apps were from Baidu, 3.9 percent apps were from pre-installed apps, and 2 percent apps were from Google.

Advertisement

These secret backdoors and blacklists on apps can allow for remote login, reset user passwords, stop users from accessing content, and let hackers bypass payment interfaces. All of these exist without any user knowledge, and this poses as another great threat in the chaotic Android ecosystem.


OnePlus 8 leaks look exciting but when will the phones launch in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  2. Redmi A7 Bags Thailand's NBTC Certification, Could Launch Soon
  1. Phil Spencer Retires as Microsoft Names AI Executive Asha Sharma as Gaming CEO in Xbox Shake-Up
  2. Astronomers Find ‘Impossible’ Galaxy ACDG-2 With Virtually No Stars and a Massive Dark Matter Core
  3. Google Pixel Call Recording Reportedly Available in Additional Regions Ahead of Global Expansion
  4. Oppo Find X9 Ultra, Vivo X300 Ultra Leak: Tipster Shares Details of Anticipated 200-Megapixel Cameras
  5. Redmi A7 Could Launch Soon as Handset Bags Thailand’s NBTC Certification
  6. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  7. Hello Bachhon OTT Release Date: When and Where to Watch Vineet Kumar Singh Starrer Online?
  8. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  9. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  10. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.