Hundreds of VPN apps listed on the Apple App Store and Google Play Store contain outbound links that put users at risk of malware and unencrypted traffic, according to a new security audit. The investigation found that thousands of links from these official store pages use plain HTTP instead of secure HTTPS, redirect to expired domains or lead directly to scareware popups designed to install malicious software.
The Scope of the Vulnerability
The audit examined thousands of VPN product pages across both app stores. It found that 339 Android links and 188 iOS links use plain HTTP instead of HTTPS. This means any network eavesdropper positioned between the user and the developer's server can intercept traffic, inject malicious code or redirect the user to a harmful site. Popular apps with over 1 million downloads, including Oryx VPN and Stealth Shield VPN, were among those flagged.
Insecure links are not the only problem. The investigation uncovered several other obscured URL formats that bypass standard protections:
Active Threats From Expired Domains
When developers abandon their apps, their official web domains often expire. The audit confirmed that malicious actors are actively purchasing these expired domains to exploit the existing app store traffic. Users who trust the official Apple or Google store link are redirected to fake antivirus popups designed to scare them into downloading malware. In some cases, store links point to deleted Twitter handles, empty social media pages or even Chinese opera sites.
These threats are not theoretical. During the investigation, researchers clicked links from active store listings and encountered live scareware campaigns. The ability for such content to remain on official store pages highlights a gap in outbound link verification by both Apple and Google. When contacted, Apple declined to comment on the record but pointed to its app review guidelines. A Google spokesperson said the company is looking into the matter and will take action against apps that violate policies.
Why This Matters
The widespread reliance on unencrypted HTTP and obscured link formats means millions of VPN users face real risks even before installing an app. The VPN market is driven by promises of privacy and security, yet the store pages that promote these tools often fail to meet basic web safety standards. For users, clicking a developer website from an official store can result in malware infection, data theft or financial fraud. The problem also erodes trust in app store moderation. If expired domains and scareware links can persist on Apple and Google storefronts, users have no reliable way to distinguish safe listings from dangerous ones. This dynamic creates a window for scammers to exploit the credibility of app store brands.
Until both companies strengthen their link verification processes, consumers must take extra precautions. Always inspect a link's destination before tapping. Verify that the URL uses HTTPS. Be wary of shorteners, raw IP addresses or unexpected PDF downloads. If a store link triggers a virus warning, close the browser tab immediately and do not interact with the page.



