Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On April 11, 2025, Dark Reading reported that Appknox had identified 10 security findings in Perplexity’s Android application. The findings included transport-security gaps, weak device-integrity checks, Android task hijacking, API configuration problems, reverse-engineering weaknesses and hardcoded keys or tokens. They were reported findings from an assessment—not proof of ten attacks, ten public CVEs, or a compromise of every Perplexity user.

The original coverage has a numbering inconsistency: its headline says “10 Bugs,” while the URL says “11-bugs.” The article text describes ten findings, so this article treats the number as ten rather than inventing an eleventh issue.

What was tested—and what was not

The target was the Perplexity Android app, not the Perplexity website, API as a whole, iOS app or underlying AI models. Dark Reading attributed the assessment to Appknox and published its report on April 11, 2025. The available coverage does not identify the exact app build, Android releases, phone models, test environment or methodology. Those omissions matter: a weakness observed on one build or device cannot automatically be generalized to every Android installation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The findings also span several layers. Some concern Android-client hardening, some relate to API or browser configuration, one references an old Android platform vulnerability, and one concerns secrets embedded in the application. They therefore do not all have the same attack path or owner.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The ten reported findings at a glance

Finding Category Reported CVSS Main concern
Insecure network configuration Network hardening Not stated Network-based interception or manipulation
Missing SSL validation or certificate pinning Transport security 5.9 Server impersonation or man-in-the-middle attacks
Weak root or jailbreak detection Device integrity 6.8 Greater exposure on modified devices
StrandHogg susceptibility Android task hijacking 6.5 App imitation, overlays or deceptive prompts
Exposure to CVE-2017-13156 Platform and installation security 6.7 Application modification under affected conditions
Clickjacking User-interface security 4.8 Unintended taps or approvals
CORS misconfiguration API and browser security Not stated Unrestricted cross-origin interaction
Unobfuscated bytecode Reverse-engineering resistance Not stated Easier inspection of code and embedded data
No ADB or developer-options detection Runtime hardening Not stated Easier debugging and instrumentation
Hardcoded Google API keys or access tokens Secrets management Described as most critical Potential abuse of services or protected APIs

All ten findings and the reported scores come from Dark Reading’s April 11, 2025 coverage. The publication described some issues as high or critical risk, but those characterizations are not a formal CVSS score for every finding.

The ten findings explained

1. Insecure network configuration

Appknox reportedly found network settings that could facilitate attacks against communications. Depending on the exact Android configuration, endpoints and an attacker’s position, this could mean traffic interception, redirection or manipulation. The available report summary does not identify the manifest settings, affected endpoints or conditions required for exploitation, so it does not establish that ordinary users were remotely exposed on every network.

2. Missing SSL validation or certificate pinning

Dark Reading reported a CVSS score of 5.9 for inadequate SSL validation or certificate pinning. If an app fails to validate the server’s identity correctly, an attacker positioned to intercept traffic may impersonate a service and observe or alter communications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Certificate pinning is an additional defense, not a universal requirement for every Android app. Missing pinning is different from broken TLS certificate validation: an app can use properly validated HTTPS without pinning, while accepting an invalid certificate is a more fundamental failure. The article does not provide the tested endpoints or proof-of-concept details.

3. Weak root or jailbreak detection

The reported CVSS was 6.8. On a rooted or otherwise modified phone, malware or an attacker with elevated privileges may have more access to application files, processes and credentials. Root detection can make abuse harder or trigger safer behavior, but it is defense in depth. Its weakness does not by itself show that a normal, unmodified handset can be taken over.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

4. StrandHogg-style task hijacking

Dark Reading reported a CVSS of 6.5 for susceptibility to the StrandHogg class of Android task-management attacks. A malicious application can, under suitable conditions, imitate or overlay another app and trick a user into entering information or approving an action.

“StrandHogg” describes a family of attack techniques, not a claim that every Android release is vulnerable to one identical exploit. Practical exposure depends on Android version, security patch level, application behavior, installed malware and user interaction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Exposure to CVE-2017-13156

The report assigned a CVSS of 6.7 to exposure to CVE-2017-13156, an old Android vulnerability class that can allow modification of an installed application without invalidating its digital signature under affected conditions.

Its relevance depends on the phone’s Android release and patch level, how the app was installed and whether the vulnerable platform behavior remains present. A current, fully patched device may not have the same exposure as an older handset. The report does not identify affected Android versions or models.

6. Clickjacking

Clickjacking, reported with a CVSS of 4.8, can cause a user to activate a control different from the one they believe they are selecting. A malicious overlay or carefully constructed interface might induce an unintended approval, navigation step or disclosure.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

This generally requires a malicious app, overlay or specific interaction. It is not equivalent to an attacker remotely controlling the Perplexity app without user involvement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. CORS misconfiguration in API responses

The coverage said Perplexity API responses allegedly allowed any website to communicate with the back end. Cross-Origin Resource Sharing is a browser-enforcement mechanism. A permissive policy can let a malicious site make or read requests that should be restricted when the right authentication and browser conditions exist.

Permissive CORS does not automatically defeat server-side authentication or authorization. The actual impact would depend on which endpoints accepted browser credentials, what data they returned and whether other controls blocked the request.

8. Unobfuscated bytecode

Unobfuscated Android bytecode is easier to reverse engineer. An analyst may more quickly map application logic, identify endpoints, understand authentication flows or locate embedded values. Obfuscation can raise the cost of analysis, but it is not encryption and cannot protect a secret that must be shipped inside the client.

9. No ADB or developer-options detection

The app allegedly did not detect Android Debug Bridge or enabled developer options. That can make debugging, instrumentation and controlled analysis easier. ADB and developer options are legitimate tools used by developers and power users, however. Detection is a hardening choice, not proof that the app is compromised whenever either feature is enabled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

10. Hardcoded Google API keys and access tokens

Dark Reading described embedded Google API keys or access tokens as the most critical issue. Values packaged in an APK can be extracted. If they are insufficiently restricted, attackers may use them to consume quotas, call services, bypass intended client controls or reach protected APIs, potentially affecting data confidentiality or integrity.

A Google API key is not automatically an unrestricted credential. Impact depends on restrictions, scopes, expiration, server-side validation and whether a token represents a user or merely an application. The report summary does not identify the key names, permissions or whether the values remained valid after publication.

How serious was the assessment?

Risk should be judged finding by finding rather than by adding ten numbers together. Four questions provide a more useful picture:

  • Exploitability: Does an attacker need a hostile network, a malicious website, another installed app, root access or only a user click?
  • Privilege: Would exploitation expose public app data, an account, an API credential or an administrative function?
  • User interaction: Must the victim install software, accept a prompt or tap a deceptive control?
  • Remediation: Was the issue fixed by an app update, mitigated by Android or merely made more difficult?

The available coverage does not establish in-the-wild exploitation, stolen user data, remote code execution or account takeover. It also does not provide a CVSS score for every finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are Perplexity users currently at risk?

The report describes a historical assessment of a particular app state, but the exact tested version is not available. The current Google Play listing reported an update on July 9, 2026, showing continued development. It does not document whether each 2025 finding was fixed, whether reported keys were rotated or whether all affected versions were remediated.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

The listing showed more than 100 million downloads and roughly two million reviews when crawled. Its developer-provided Data Safety section says the app may share app activity, app information and performance data, and device or other IDs; it may collect location, personal information and other data; data is encrypted in transit; and deletion can be requested. Google cautions that these disclosures are supplied by developers and may vary by use, region, age and app version. See Google’s Data Safety explanation.

Continued updates are not proof that every historical weakness was corrected. Conversely, the report is not proof that the current release remains vulnerable.

What Android users should do

  1. Update through Google Play. Confirm that the developer is Perplexity AI, Inc. The later listing update is a reason to install current software, not evidence that every finding was fixed.
  2. Install Android security updates. This is particularly important for old platform-level issues such as StrandHogg-related attacks and CVE-2017-13156.
  3. Avoid modified APKs and unofficial builds. Sideloaded packages add supply-chain and tampering risks.
  4. Use extra caution on rooted or heavily modified devices. Do not use such a phone for sensitive Perplexity work unless you understand the additional exposure.
  5. Do not treat the app as a secure vault. Avoid entering passwords, recovery codes, financial credentials, regulated personal data or confidential business material unless your organization has approved that use.
  6. Review account sessions and connected services if you used an old build and have concrete reason to suspect compromise.
  7. Report problems with useful details. Include the phone model, Android version and app version when contacting [email protected].

Uninstalling was reportedly recommended by the original researchers as an interim precaution. It should not be treated as an automatic requirement for every user in 2026 without confirmation that the current build is affected. If you cannot update, use a rooted or unsupported device, or handle highly sensitive information, temporary removal is a reasonable risk-reduction choice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What developers should learn

  • Keep reusable credentials out of mobile clients; use narrowly scoped, replaceable credentials and rotate anything exposed.
  • Enforce certificate validation and secure transport, while recognizing that pinning has operational trade-offs.
  • Apply authorization on the server regardless of client-side checks, obfuscation or root detection.
  • Review exported components, overlay protections, WebView behavior and browser-facing CORS policies.
  • Test release builds on rooted, debug-enabled and instrumented devices.
  • Use release obfuscation to reduce unnecessary disclosure, but never rely on it to protect secrets.
  • Publish affected versions, remediation dates and clear user guidance when a security issue is found.

App security is not AI-model safety

These findings concern a mobile application and related API behavior. They do not establish problems with model hallucinations, prompt injection, citation accuracy or AI alignment. Those are separate security, privacy and quality questions. Likewise, a finding in the Android client does not automatically apply to Perplexity’s website, iOS app or every backend service.

Should you switch to another AI assistant?

ChatGPT, Gemini and Claude all offer official products and Android distribution, but this report does not support ranking them as safer. A switch may be appropriate if your organization cannot approve the current Perplexity risk, but compare the controls that matter to your use case:

  • Android update history and security response process.
  • Data retention, training controls and deletion options.
  • Account-session management and enterprise administration.
  • Permissions for voice, camera and screen features.
  • Search, citation and integration requirements.
  • Whether sensitive work can remain inside an approved organizational environment.

Official links: ChatGPT and its Android app; Gemini and its Android app; and Claude with its Android app. None should be assumed secure without comparable, current evidence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.