Apps installed on devices leaked: what it means and what to do

Risk level: medium. Can you change it: yes. Found in 1 breaches in this directory.

What this data is

An inventory of the applications present on your phone or computer, collected by an app, an advertising kit or a device management tool. It usually includes package names and sometimes versions.

The risk on its own

The list is a personality profile you never agreed to publish. Dating apps, faith apps, recovery apps, community apps, gambling apps and mental health apps all say something intimate about a person. Old app versions also tell an attacker which known weaknesses your device still has.

The risk combined with other data

Joined to your name, email or device ID the inventory becomes a targeting map. An attacker knows which bank you use, which wallet you hold and which authenticator you rely on, so the phishing page they build matches your actual apps. For some people the presence of a single app is itself dangerous information.

How criminals use it

  • A phishing page is cloned from the exact banking app you have installed, rather than a generic one.
  • The presence of a dating, faith or recovery app is used for blackmail or for outing someone.
  • An attacker sees you run an outdated version of an app with a public weakness and aims at that.
  • Fraudsters see a crypto wallet app on the list and move you to the top of the target queue.

What to do now

  1. Delete apps you no longer use, which shrinks both the profile and the attack surface.
  2. Turn on automatic updates so old versions are not advertising known weaknesses.
  3. Review app permissions: on iPhone in Settings, Privacy and Security, on Android in Settings, Security and privacy, Permission manager.
  4. On Android open Settings, Google, Ads and reset your advertising ID. On iPhone open Settings, Privacy and Security, Tracking and switch off allow apps to request to track.
  5. Change the password on the service that leaked the list and review what else it collected.

Frequently asked questions

How can an app see what else I have installed?

Some platforms allow a query for installed packages, and advertising kits built into free apps have collected it for years to build profiles for targeting.

Is this actually harmful?

For most people it is a privacy problem rather than a financial one. For anyone whose safety depends on a single app staying private, it can be serious.

Does deleting the app now remove me from the leaked list?

No. The copy taken is fixed. Deleting unused apps reduces what the next collection can see.

Breaches that exposed this data

  • ai.type: 2017-12-05, 21M accounts, Address book contacts, Apps installed on devices, Cellular network names, Dates of birth, Device information, Email addresses

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.