Android Network Security: What Your Apps Are Really Sending
We analysed 100 popular Android apps with Firewall Lens. The results were sobering. Here's what we found and what you can do about it.
When we built Firewall Lens, we knew Android apps sent a lot of data. We didn't know how much until we started looking systematically.
The Methodology
We tested 100 apps from the Play Store top charts across 10 categories: social, productivity, games, finance, health, news, shopping, utilities, travel, and communication. Each app was run for 30 minutes of normal use on a factory-reset device with Firewall Lens capturing all network traffic.
Key Findings
Finding 1: 73% of apps contacted ad/tracking domains within the first 60 seconds of launch — before any user interaction.
This is the app-level equivalent of a shop assistant following you around with a clipboard. Most users have no idea it's happening.
Finding 2: The average app made 47 unique domain connections per 30-minute session.
Of these, roughly 30% were to first-party servers, 40% to ad networks and analytics, and 30% to undefined third parties.
Finding 3: 12 apps transmitted device identifiers (IMEI/MAID) in plaintext over HTTP.
This is a GDPR/CCPA violation in most jurisdictions. Several of these apps had over 10 million downloads.
What You Can Do
For end users, Firewall Lens gives you per-app blocking rules so you can cut tracker connections while keeping the apps you love functional.
For developers, the lesson is to audit your dependencies. Many SDKs you pull in bring their own analytics — you may be sending data you didn't explicitly authorise.
For enterprises, a device-level firewall policy should be part of your mobile device management (MDM) configuration. The data leaving your employees' work devices may surprise you.