New controversies of Chinese mobiles sold in China arrive. And it is that a recent study analyzes how some devices marketed in this country include “spy apps” that transmit device information and personal data to third parties. And, presumably, without consent.
This study has reviewed the Chinese ROM that some manufacturers include like Xiaomi, OPPO, OnePlus and Realme on their devices. And it is important to clarify this, since the firmware and software that the devices bring in Europe and other territories is different.
Sharing information with third parties in the background and without user permission
The investigation has been carried out by several security researchers belonging to various Irish universities. In it they have focused on the mobiles sold in china, having on the table the aforementioned manufacturers. It is worth noting the territory, since the investigation has been done on Chinese software and not the one that reaches us in Europe.
In these terminals we find different AOSP (Android Open Source Project) packages. They include third-party packages with Chinese firmware that derives in “native” apps running behind-the-scenes tracking in the background.
As an example we have Baidu Map as a GPS navigation app that behind it has AMap running in the background to log user locations. The study also talks about other news, video playback or online shopping applications that contain hidden packages.
The data is sent to some Chinese operators even if the mobile does not have a SIM or it is from a different operator.
The researchers say that without the user having given their consent, this data is passed on to third parties of all kinds and despite the fact that the option “Send usage and diagnostic data” is deactivated. And this information is not only sent to device manufacturers, but also to app service providers and Chinese operators. What is striking in this last case is that this information reached operators other than those of the SIM. Even in the tests they did without inserting a SIM, they discovered that they transmitted data to them.
between that information that was sent they highlight device identifiers such as their IMEI, user location, phone number, behavior they maintained while using the app, call history, SMS content, and even contacts. The seriousness of this issue is highlighted by researchers for the inability to use the smartphone anonymouslyalso counting that in China each telephone number is registered with a citizen identification.
And while it is true that the investigation does not speak about the global software with which these Chinese phones come to Europe or America, they do highlight the fact that the information continues to be collected even when the user leaves China. In other words, not even on your trips will you be free to transmit this data in the background to the previous parties involved.
The study only reveals what happens with mobiles sold in and for China
If you have a mobile from one of the aforementioned manufacturers, don’t worry. As we said at the beginning, this study affects the Chinese versions of the mobiles of these brands, but not in european versions. There is no evidence that this study has been carried out with the global ROM of each one, but to this day there are no controversies like this with these terminals.
In any case, from crast.net Mvil we have contacted the manufacturers involved in this investigation. At the moment they have not issued statements in this regard, although we will update this article with all the information they would like to provide us.
Via | The Register
More information | Cornell University
