Originally reported by Sam Bent
TL;DR
Security researcher Sam Bent identified serious privacy issues in federal mobile applications, including the White House app shipping with a sanctioned Chinese tracking SDK and FEMA requesting 28 permissions for basic weather alerts.
Government apps containing sanctioned Chinese SDKs represents a significant privacy and security concern, though no active exploitation is confirmed. The excessive permissions and tracking behavior warrant attention from security practitioners.
Security researcher Sam Bent has documented concerning privacy practices across 13 federal government mobile applications, revealing a pattern of excessive data collection that mirrors the behavior of apps these same agencies have previously flagged as security risks.
The official White House mobile application ships with a tracking SDK from a sanctioned Chinese company, according to Bent's analysis. This represents a significant supply chain security failure, as federal agencies have previously warned against applications containing similar tracking components from Chinese vendors.
The presence of sanctioned tracking technology in an official government application raises questions about app vetting processes and supply chain oversight within federal IT procurement.
Bent's research identified a broader pattern of aggressive data collection across federal apps:
These permission requests often exceed what commercial apps require for similar functionality, suggesting inadequate privacy-by-design implementation in federal mobile development.
The findings highlight several critical security concerns:
The research exposes a disconnect between federal cybersecurity guidance and internal practices. Agencies that have issued warnings about foreign tracking SDKs and excessive app permissions are deploying similar technologies in their own mobile applications.
This pattern suggests inadequate application of the same security standards internally that agencies recommend for private sector and citizen use.
Security teams should consider:
https://www.sambent.com/the-white-house-app-has-huawei-spyware-and-an-ice-tip-line/
Originally reported by Sam Bent