A new security audit reveals that 10 Android mental health apps with more than 14.7 million combined Google Play installs have serious security flaws that could expose highly sensitive user data. Security firm Oversecured examined widely used mood trackers, AI “therapy” chatbots, therapy‑based anxiety tools, and online teletherapy apps that claim to help with conditions like depression, anxiety, and PTSD. It found 1,575 vulnerabilities across the 10 apps, including 54 high‑risk, 538 medium‑risk, and 983 low‑risk issues.
The audit looked at the latest public versions of these apps from late January 2026. By focusing largely on how the apps store and process personal information, researchers found weaknesses in link handling, data storage, and cryptography. In some apps, the code exposes backend endpoints and database URLs. Attackers can use this information to better understand the infrastructure, which can then inform the planning of specific attacks.
The affected apps collect and store sensitive information like chat transcripts, mood logs, therapy notes, medication details, and self‑harm indicators. Oversecured founder Sergey Toshin says mental health records can fetch up to around $1,000 per profile on underground markets, making these apps a prime target for opportunistic hackers.
Oversecured has begun disclosing these vulnerabilities to developers. Some apps have received crucial security updates, but others have not been patched for several months. Disappointingly, Oversecured has not released a public list of affected apps, but it reportedly includes apps with FDA Breakthrough Device designations for the treatment of depression, as well as those widely used by state healthcare programs in Europe.

