Magazine Home
App Trap
The Computer Corner

Español
August 16, 2026

by Charles Miller

Last week I made the statement that there are some serious security consequences associated with having many apps installed on your smartphone. This week I will take time to explain how having a large number of unused apps on your smartphone creates a real and present threat scenario that potentially compromises your online security.

There is a reason why the best practice is not to download or install apps from unknown sources. Apps found on the Apple's App Store and the Google Playstore have been subjected to proper security vetting to ensure they do not include malware or "features" that violate good practice. Both Apple and Google do an outstanding job of running a clean store, yet criminals are nothing if not incessant in finding ways to sneak their malicious apps into the stores and thus into your phone.

There are a lot of apps available for smartphones that were created by individuals or small companies. Sometimes the author of an app loses interest in maintaining it, or maybe he or she gets a real job and no longer has time to improve or maintain their app. Cybercriminals look for these situations, an app that is or has been popular, but is no longer being actively improved by its creator. They especially look for such "orphaned" apps that have been around for years and have good reputations. The crooks offer to buy the rights to such apps from the author, and developers who have lost interest or who are tempted by a little quick cash might sell their rights.

If the author sells to the crooks, or if the crooks somehow otherwise gain access to the author's accounts, they can quietly push out an "update" containing malware to all existing users who still have that app that used to come from a trusted source.

This is a bit of a blind spot for Apple and Google. While both companies usually do a very thorough job of checking new apps for malware, the same cannot be said for the seemingly endless waves of monthly or even daily updates. If an update to a trusted app includes malicious content, that is more likely to fly under the radar and be pushed out to thousands or millions of unsuspecting smartphones users without Apple or Google being aware.

The criminals might take the slow approach of not making the app obviously malicious right away. They could push out seemingly normal updates while quietly adding malicious functionality, such as watching your keystrokes in hope of stealing your banking credentials. This stealth approach helps the malware avoid detection for longer.

This is why you should not have apps on your smartphone that you do not use regularly. You are more likely to install updates to apps you have had for years and trust. It can take time for Apple or Google security teams to detect malicious behavior, and by then your bank account could have been emptied out. This has actually happened.

The protection strategy to avoid this is obvious. Use only apps obtained from the official Apple or Google stores. Be vigilant; if a weather app suddenly asks for permission to access your camera or passwords then it is probably up to o good. Most of all, uninstall every app you do not use on a regular basis.

**************

Charles Miller is a freelance computer consultant with decades of IT experience and a Texan with a lifetime love for Mexico. The opinions expressed are his own. He may be contacted at 415-101-8528 or email FAQ8 (at) SMAguru.com.

**************
*****

Please contribute to Lokkal,
SMA's online collective:

***

Discover Lokkal: Mission


Visit SMA's Social Network

Contact / Contactar

Subscribe / Suscribete  
Click ads

Contact / Contactar


copyright 2026