search
HomeTechnology peripheralsAIPerplexity's Android App Is Infested With Security Flaws, Report Finds

Perplexity’s Android App Is Infested With Security Flaws, Report Finds

But the company’s Android app, which offers not only search capabilities but also acts as an AI assistant, is riddled with a host of security issues that could expose its users to data theft, account takeovers and impersonation attacks from malicious hackers, according to a report by India-based mobile security company Appknox. One of these gaps also lets anyone access Perplexity’s API for free, exposing the company itself to the risk of losing revenue.

Security researcher and Appknox CEO Subho Halder said it’s easy to make clones of Perplexity’s Android app because its code is embedded with what’s called “hardcoded secrets” — sensitive information like passwords and API keys (a string of alphabets and numbers that is used to identify and verify an application making requests to use that API), which can be extracted by an attacker. The cloned app can then be used to trick users into believing it’s the real one, enabling hacks to collect private data like login information and uploaded documents.

Perplexity rolled out its agent-like AI assistant for Android devices in January, which it claimed could carry out tasks like booking an Uber, playing a video on YouTube, finding songs on Spotify and making reservations all on its own. But the slew of security flaws has been uncovered just as Perplexity, reportedly in talks to raise funding at an $18 billion valuation, tries to find new ways to distribute its mobile app to more users and put it in more people’s hands. The company is in talks with smartphone manufacturing giant Samsung to integrate its AI assistant into their phones and it has already reached an agreement with Lenovo-owned Motorola to do the same, according to Bloomberg. Perplexity did not respond to a request for comment.

Perplexity’s app is also susceptible to an attack called “task hijacking” in which a rogue app takes control of the phone’s actions without your knowledge as you use a different one. The now-malicious app can then monitor your activity and collect data. For example, someone could hack Perplexity’s app so that if you’re typing a prompt into Amazon’s search box, it could unknowingly give hackers access to it. Halder said it could even fall prey to network-based attacks where people on an unsecured network such as an airport hotspot can have their conversations with Perplexity intercepted and their data stolen.

Founded in 2022, Perplexity’s first product was a conversational AI search engine that crawls the web for information and uses a mix of large language models from OpenAI, Anthropic and Meta to answer questions on any given topic by producing AI-generated summaries that include links to sources from across the web. It has raised a total of $900 million in venture funding from tech bigwigs like Amazon founder Jeff Bezos and OpenAI cofounder Andrej Karpathy and is currently valued at $9 billion, according to Pitchdeck. Perplexity’s app has more than 10 million downloads on Google Play.

Security vulnerabilities are just part of the problem for Perplexity. The company has come under fire from Forbes and other media outlets for allegedly plagiarizing their reporting and redistributing it across multiple platforms through a feature called Perplexity Pages. At the time, Srinivas said that its republishing product feature had “rough edges” and that Perplexity was “improving it with more feedback.” In June 2024, Forbes sent a cease-and-desist letter to Perplexity, accusing it of infringing copyright, to which the Perplexity responded saying the claims were meritless and that factual information is not protected by copyright law.

Safety in the world of AI often focuses on the models themselves–ensuring that they’re producing accurate information and aren’t affected by bias. This report underscores the idea that securing the application where people interact with the models is just as important, Halder told Forbes.

Halder’s advice to users is to remove Perplexity’s Android app from the phone until the issues are resolved. AI applications are being built at a breakneck speed and many are failing on the most basic vulnerability checks, Halder said, but “Perplexity is a full-blown security hazard.”

MORE FROM FORBES

ForbesThis Tech Incubator Is Harder To Get Into Than HarvardBy Richard NievaForbesThis AI Founder Has Unseated Taylor Swift As The World’s Youngest Self-Made Woman BillionaireBy Kerry A. DolanForbesNew Data Shows Just How Badly OpenAI And Perplexity Are Screwing Over PublishersBy Rashi ShrivastavaForbesBuzzy AI Search Engine Perplexity Is Directly Ripping Off Content From News OutletsBy Sarah Emerson

The above is the detailed content of Perplexity's Android App Is Infested With Security Flaws, Report Finds. For more information, please follow other related articles on the PHP Chinese website!

Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Tesla's Robovan Was The Hidden Gem In 2024's Robotaxi TeaserTesla's Robovan Was The Hidden Gem In 2024's Robotaxi TeaserApr 22, 2025 am 11:48 AM

Since 2008, I've championed the shared-ride van—initially dubbed the "robotjitney," later the "vansit"—as the future of urban transportation. I foresee these vehicles as the 21st century's next-generation transit solution, surpas

Sam's Club Bets On AI To Eliminate Receipt Checks And Enhance RetailSam's Club Bets On AI To Eliminate Receipt Checks And Enhance RetailApr 22, 2025 am 11:29 AM

Revolutionizing the Checkout Experience Sam's Club's innovative "Just Go" system builds on its existing AI-powered "Scan & Go" technology, allowing members to scan purchases via the Sam's Club app during their shopping trip.

Nvidia's AI Omniverse Expands At GTC 2025Nvidia's AI Omniverse Expands At GTC 2025Apr 22, 2025 am 11:28 AM

Nvidia's Enhanced Predictability and New Product Lineup at GTC 2025 Nvidia, a key player in AI infrastructure, is focusing on increased predictability for its clients. This involves consistent product delivery, meeting performance expectations, and

Exploring the Capabilities of Google's Gemma 2 ModelsExploring the Capabilities of Google's Gemma 2 ModelsApr 22, 2025 am 11:26 AM

Google's Gemma 2: A Powerful, Efficient Language Model Google's Gemma family of language models, celebrated for efficiency and performance, has expanded with the arrival of Gemma 2. This latest release comprises two models: a 27-billion parameter ver

The Next Wave of GenAI: Perspectives with Dr. Kirk Borne - Analytics VidhyaThe Next Wave of GenAI: Perspectives with Dr. Kirk Borne - Analytics VidhyaApr 22, 2025 am 11:21 AM

This Leading with Data episode features Dr. Kirk Borne, a leading data scientist, astrophysicist, and TEDx speaker. A renowned expert in big data, AI, and machine learning, Dr. Borne offers invaluable insights into the current state and future traje

AI For Runners And Athletes: We're Making Excellent ProgressAI For Runners And Athletes: We're Making Excellent ProgressApr 22, 2025 am 11:12 AM

There were some very insightful perspectives in this speech—background information about engineering that showed us why artificial intelligence is so good at supporting people’s physical exercise. I will outline a core idea from each contributor’s perspective to demonstrate three design aspects that are an important part of our exploration of the application of artificial intelligence in sports. Edge devices and raw personal data This idea about artificial intelligence actually contains two components—one related to where we place large language models and the other is related to the differences between our human language and the language that our vital signs “express” when measured in real time. Alexander Amini knows a lot about running and tennis, but he still

Jamie Engstrom On Technology, Talent And Transformation At CaterpillarJamie Engstrom On Technology, Talent And Transformation At CaterpillarApr 22, 2025 am 11:10 AM

Caterpillar's Chief Information Officer and Senior Vice President of IT, Jamie Engstrom, leads a global team of over 2,200 IT professionals across 28 countries. With 26 years at Caterpillar, including four and a half years in her current role, Engst

New Google Photos Update Makes Any Photo Pop With Ultra HDR QualityNew Google Photos Update Makes Any Photo Pop With Ultra HDR QualityApr 22, 2025 am 11:09 AM

Google Photos' New Ultra HDR Tool: A Quick Guide Enhance your photos with Google Photos' new Ultra HDR tool, transforming standard images into vibrant, high-dynamic-range masterpieces. Ideal for social media, this tool boosts the impact of any photo,

See all articles

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Atom editor mac version download

Atom editor mac version download

The most popular open source editor

Dreamweaver Mac version

Dreamweaver Mac version

Visual web development tools

PhpStorm Mac version

PhpStorm Mac version

The latest (2018.2.1) professional PHP integrated development tool

mPDF

mPDF

mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

EditPlus Chinese cracked version

EditPlus Chinese cracked version

Small size, syntax highlighting, does not support code prompt function