HUAWEI

AppWizard
August 9, 2026
Third-party advertising tools embedded in Android applications are automatically collecting location data, often without the app developers' awareness. Software development kits (SDKs) used for advertising come with location data collection enabled by default, unless developers actively disable this feature. Historical location data has been sold to military and intelligence agencies, including the FBI, and used in immigration enforcement actions in the US. The Electronic Frontier Foundation (EFF) reported that app-level location permissions do not provide meaningful consent for location collection by third-party advertising SDKs. The EFF identified four advertising SDKs—InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads—that collect and share location data by default. Two analyzed apps had been downloaded 60 million times without providing a privacy notice or seeking user consent for third-party location sharing. Users can manage location permissions through their device settings, but the EFF emphasizes that developers should ensure user data is not shared by default.
AppWizard
August 6, 2026
A report from the Electronic Frontier Foundation (EFF) highlights concerns about third-party software development kits (SDKs) in mobile applications collecting and sharing user location data with advertising companies, often without user consent. Many developers use these advertising SDKs for monetization, but their default settings allow for location data collection. This data is sent to advertising companies and location data brokers, which can misuse it in sensitive contexts. Users may unknowingly expose their location data when granting permissions to apps, as third-party SDKs can access this information without clear user awareness. The EFF identified several advertising SDKs, including InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads, that collect and share location data by default. Developers are encouraged to review SDK settings to protect user privacy, and the EFF calls for regulatory scrutiny of data harvesting practices.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
AppWizard
July 31, 2026
Bitsight's investigation revealed that inexpensive Android TV boxes are being shipped with applications that can change their hardware identity, allowing them to impersonate popular smartphone brands like Samsung and Huawei. This operation, named Fuyao, is linked to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese company established in 2019. The H96MAXV11 model was frequently reported among the affected devices. In one day, the operation received 65,957 reports from about 38,000 unique MAC addresses, with many devices misidentified as phones due to spoofed identifiers. Fengwo has also promoted over 120,000 "AI digital humans," though details on this marketing term are vague. The command-and-control server for Fuyao sends phone profiles to devices, masking their actual hardware specifications. The operation uses machine vision technology and a YOLOv8s object-detection model to identify advertisements. Bitsight documented 40 fraud tasks, 21 unique campaigns, and 166 modules across four devices. The operation's payout structure involves 144 operator-owned domains, with an estimated gross return of .25 per device daily, potentially leading to annual revenues in the millions. Attribution to Fengwo is supported by shared TLS certificate data and public patent records, although the patents do not directly address advertising. There is uncertainty about how the fraudulent apps were installed and at what point in the supply chain they were introduced. Device owners are advised to verify Play Protect certification and disconnect suspicious devices.
AppWizard
July 29, 2026
Purchasing a Samsung Galaxy Watch does not grant access to all its features unless paired with a Samsung Galaxy smartphone, despite owning a new Android device. The Samsung Health Monitor app, which includes critical health monitoring features like blood pressure, ECG, irregular heart rhythm, and sleep apnea monitoring, is only officially supported on Samsung smartphones. This app has been available since 2020 and is essential for detecting significant health indicators. Samsung's limitation on the app appears to be financially motivated, as it encourages users to buy Samsung smartphones. Other manufacturers do not impose similar restrictions, allowing their devices' full health features to work across different smartphone brands. Samsung could integrate Health Monitor features into the main Samsung Health app or make it available on the Play Store to increase accessibility, but it has not done so. Users of non-Samsung Android phones are unable to access these health features, which are critical for many individuals.
Winsage
July 23, 2026
Huawei will launch its first PCs powered by HarmonyOS in September, aiming to reduce China's reliance on Windows and create a homegrown computing ecosystem. The rollout will initially target government departments, financial institutions, and enterprise customers. HarmonyOS has been developed in response to U.S. sanctions, which restricted Huawei's access to Google services, advanced chips, and Windows licensing. The operating system has achieved high-level Chinese security certifications, making it suitable for sensitive government use. Huawei plans to build an interconnected ecosystem similar to Apple's, integrating HarmonyOS laptops with its other devices.
AppWizard
July 17, 2026
The government has mandated that all work-related communications for state and municipal employees must transition to the "Max" messenger platform by 2030. The "Max" platform was developed by "Kommunikatsionnaya platforma," with a beta version launched in March 2025 and becoming a mandatory pre-installed application on new smartphones in Russia by September 2025. As of March 2026, "Max" had 100 million registered users and offered features like audio/video calls, chat, voice messaging, large file sharing, and money transfers. In July, the EU imposed sanctions on VK, the parent company of "Kommunikatsionnaya platforma," and "Max" was removed from the Apple App Store in June and from Google Play recently. VK stated that its services remain functional and are available on alternative platforms such as RuStore and Huawei AppGallery. Negotiations with Apple are ongoing to restore "Max" to the App Store.
AppWizard
July 17, 2026
VK's core applications, including the VK social network and Max messenger, have been removed from the Google Play store and previously from the Apple App Store. Users searching for these apps will find them absent, and this may be linked to recent international sanctions. VK's press service stated that users who have the apps installed will not experience disruptions, and all features and security systems will remain stable. Users are encouraged to download the apps from alternative platforms, such as RuStore, Huawei AppGallery, Samsung Galaxy Store, and Xiaomi GetApps. Additionally, the Odnoklassniki social network application has also disappeared from the Google Play store. The European Union has imposed sanctions against VK and its subsidiary, "Kommunikatsionnaya platforma," which is linked to the removal of these applications from major tech platforms.
AppWizard
July 17, 2026
VK announced on July 16 that its Max messenger and VKontakte applications have been removed from the Google Play app store, along with the Odnoklassniki app. Users can still access these apps through alternative platforms like RuStore, Huawei AppGallery, Samsung Galaxy Store, and Xiaomi GetApps, and functionality will remain uninterrupted for those who have already installed them. VKontakte users are receiving notifications about a transition from the .com domain to .ru, assuring them of the platform's reliability. This change follows sanctions imposed by the European Union on July 13 against VK and its subsidiary, Kommunikatsionnaya Platforma. In late June, the Max messenger and VK social network app, along with Mail.ru’s email applications, were also removed from the App Store, with Odnoklassniki becoming unavailable at that time.
AppWizard
July 16, 2026
VK has announced its decision to sell 100% of RuStore to Dmitry Pankrushev, the CEO of Mnogo Prilozheniy. This announcement coincided with recent European Union sanctions against VK. RuStore was established as a domestic alternative for Android users in response to restrictions imposed by Apple and Google after Russia's invasion of Ukraine in 2022. The platform currently features over 110,000 applications and games, attracting 68 million monthly users. VK did not disclose the financial details of the sale or the reasons behind the divestment, while assuring users that operations would continue seamlessly. On the same day, Russian media reported that VK-related applications were removed from Google Play and Huawei's AppGallery, following previous removals from Apple's App Store. RuStore has faced allegations of user tracking and unauthorized access to data, which it denies, stating that its practices are standard for major app storefronts.
Search