---
title: Connected Objects, Vulnerable to Malicious Takeover
description: Official stores list hundreds of mobile applications enabling to control their connected objects. But how protected are these apps in case of an attack? How do they secure the data they handle? Vulnerability, uncertified servers connections... Discover our analysis of 100 IoT applications.
image: https://blog.pradeo.com/hubfs/iot_pradeo.jpg
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Mobile Security](https://blog.pradeo.com/topic/mobile-security)

# Connected Objects, Vulnerable to Malicious Takeover

![Picture of Vivien Raoul](https://blog.pradeo.com/hubfs/vivien-raoul.jpg)

 By [Vivien Raoul](https://blog.pradeo.com/author/vivien-raoul) on March, 27 2018

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![iot\_pradeo.jpg](https://blog.pradeo.com/hubfs/iot_pradeo.jpg)

In a few years, smart cars will become common and they will drive you wherever you want autonomously. We are not at that stage yet, but we can already **control our entire house** thanks to home automation. Heaters, lights, door-locks or CCTV are now connected items that can be managed remotely from a mobile phone or a tablet through a **dedicated mobile application**.

Official stores are listing hundreds of [mobile applications](https://blog.pradeo.com/mobile-application-security-testing-a-must-do) enabling to control **connected objects**. Once installed, these applications can influence users environment and access their private information: videos, pictures, location, etc. But how protected are they in case of an attack? How do they secure the data they handle?

The Pradeo Lab investigated the question by reviewing a representative sample of **100 IoT mobile applications** (thermostat, electrical blinds, remote control, baby phone…) available on Google Play and App Store. Discover below the main results from this study.

 

## 15% of applications are vulnerable to takeover

80% of tested applications carry vulnerabilities, with an average of 15 per application. Moreover, 15% of them can lead to a [Man-In-The-Middle](https://blog.pradeo.com/man-in-the-middle-attack) attack, a vulnerability that particularly caught our researchers' attention because in the IoT realm, it can lead to an object takeover by a cybercriminal.

## 8% of applications get connected to uncertified networks

Official stores applications rarely include a malware but they are not necessarily safe. The IoT applications analyzed by the Pradeo Lab are sending the data they handle to 17 servers in average, and 8% of them are transmitting the information to uncertified servers. Among these, some have expired and are available for sale. Anyone buying them could access all the data they receive.

 

## 90% of applications leak the data they manipulate

Most of the analyzed applications are sending data over the network. Here is the detail of the data sent classified by the percentage of applications which send them:

- Application file content: 81% of applications
- Hardware information (device manufacturer, commercial name, battery status…): 73%
- Device information (OS version number…): 73%
- Temporary files: 38%
- Phone network information (service provider, country code…): 27%
- Video and audio records: 19%
- Files coming from app static data: 19%
- Geolocation: 12%
- Network information (IP address, 2D address, Wi-Fi connection state): 12%
- Device identifiers (IMEI): 8%

 

We have reached out to the companies concerned by these results to notify them about the security problems they are exposed to.

---

 

Discover Pradeo Security, the [behavioral analysis engine](https://www.pradeo.com/en-US/pradeo-security) which contributed to this detailed analysis.

 

###### About The Author

[More from this author](https://blog.pradeo.com/author/vivien-raoul)

![](https://blog.pradeo.com/hs-fs/hubfs/vivien-raoul.jpg?height=100&name=vivien-raoul.jpg)

###### Vivien Raoul

#### Recommended articles

[![Smartphones: massive data leaks… that are perfectly legal](https://blog.pradeo.com/hubfs/Template%20article%20(14)-1.png)](https://blog.pradeo.com/smartphones-massive-data-leaks-that-are-perfectly-legal)

###### [Smartphones: massive data leaks… that are perfectly legal](https://blog.pradeo.com/smartphones-massive-data-leaks-that-are-perfectly-legal)

 \- December 18, 2025

[![Mobile threats: what the new ANSSI report reveals](https://blog.pradeo.com/hubfs/Template%20article%20(11)-1.png)](https://blog.pradeo.com/mobile-threats-what-the-new-anssi-report-reveals)

###### [Mobile threats: what the new ANSSI report reveals](https://blog.pradeo.com/mobile-threats-what-the-new-anssi-report-reveals)

 \- December 4, 2025

[![Techstep chooses Pradeo to provide next-level Mobile Threat Defense to its users](https://blog.pradeo.com/hubfs/Template%20article%20(13).png)](https://blog.pradeo.com/techstep-chooses-pradeo-to-provide-next-level-mobile-threat-defense-to-its-users)

###### [Techstep chooses Pradeo to provide next-level Mobile Threat Defense to its users](https://blog.pradeo.com/techstep-chooses-pradeo-to-provide-next-level-mobile-threat-defense-to-its-users)

 \- November 20, 2025

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 27 March, 2018

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 27 March, 2018

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 27 March, 2018

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 27 March, 2018

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 27 March, 2018

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Vivien Raoul"
  },
  "dateModified" : "January 27, 2021, 2:21:01 PM",
  "datePublished" : "2018-03-27 12:00:41",
  "description" : "Official stores list hundreds of mobile applications enabling to control their connected objects. But how protected are these apps in case of an attack? How do they secure the data they handle? Vulnerability, uncertified servers connections... Discover our analysis of 100 IoT applications.",
  "headline" : "Connected Objects, Vulnerable to Malicious Takeover",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://cdn2.hubspot.net/hubfs/2378615/iot_pradeo.jpg"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```