A public advisory from the FBI is urging iPhone and Android users to think harder about where the apps on their phones actually come from, and where the data those apps gather ends up. The bureau’s warning centers on mobile applications developed and maintained by companies headquartered in China, and it makes an uncomfortable case: some of the most widely downloaded apps in the United States may be quietly routing personal information to servers overseas, in ways ordinary users have no way to see.
The concern is not that a phone will visibly misbehave. It is that data collection can happen silently in the background, folded into apps that look and function exactly as expected. That invisibility is precisely what the advisory is meant to counter, by pushing users to weigh who controls an app before granting it access to the contacts, location and messages stored on a device.
What the FBI advisory actually warns about
At the heart of the warning is the legal environment in which many of these apps are built. Under China’s national-security laws, companies based there can be compelled to hand data to the government on demand, which means information collected by a popular app could, in principle, be shared with Chinese authorities regardless of what the app’s marketing suggests. The FBI’s public-service announcement frames this as a structural risk rather than an accusation about any one product, warning that foreign-controlled apps may collect far more than users realize and expose that data to a foreign government.
The types of data at stake are the intimate everyday details a phone holds. The advisory describes apps that may continuously gather information even when a user has granted permission only while the app is open, and that can pull in address-book data such as contacts’ names, phone numbers, email addresses and physical addresses through default permission settings. In practice, that means installing one app can expose information about people who never installed it at all.
Hidden code and the problem of default permissions
Beyond routine data collection, the bureau has flagged a more aggressive threat: the possibility that certain apps contain hard-to-detect malicious code. According to the FBI, some applications may carry embedded software designed to exploit weaknesses in a phone’s operating system, opening backdoors that allow unauthorized access or the download of additional harmful components. Security researchers summarizing the guidance noted that the warning applies to both iPhone and Android users, since the underlying risk lies in the app itself rather than the operating system it runs on.
Default permissions compound the problem. Many apps request broad access at installation, and users often approve those requests without scrutiny in order to start using a service. Once granted, that access can persist and operate quietly, which is why the advisory emphasizes reviewing what an app is permitted to reach rather than assuming the defaults are minimal. A permission granted once tends to stay granted until a user deliberately revokes it.
The apps most people are already using
Notably, the FBI’s advisory does not name specific applications, a deliberate choice that keeps the guidance focused on the category of risk rather than a blacklist. Coverage of the warning has pointed out that the description fits some of the most heavily used apps in the country, with commonly cited examples including the video platform TikTok and the shopping apps Shein and Temu, all of which have deep ties to Chinese parent companies and enormous American user bases. Reporting aimed at everyday smartphone owners has stressed that the alert is meant to change behavior, not just raise alarm.
The practical difficulty is that these are not obscure downloads. They are apps embedded in daily routines, used for entertainment, shopping and communication by tens of millions of people. That ubiquity is part of what makes the advisory significant: the risk it describes is not confined to a fringe of suspicious software but woven into mainstream mobile life.
What users can do about it
The advisory does not order anyone to delete a particular app, and it stops short of banning anything. Instead, it points toward a set of habits that reduce exposure. Reviewing the permissions each app has been granted, and revoking access to contacts, location or the microphone where it is not truly needed, limits how much a given app can collect. Deleting apps that are rarely used removes a data pathway entirely, and paying attention to which company actually controls an app, rather than only what the app does, helps users make an informed choice.
For those unwilling to give up a favorite service, the guidance still has value as a prompt to minimize what is shared: turning off background data collection where possible, declining broad default permissions and treating an address book as sensitive information rather than a routine grant. The broader message of the FBI’s warning is less about any single app than about a habit of mind, a recognition that the software people trust most casually can be the software gathering the most, and that the destination of that data is not always visible from the home screen.
This article was researched and drafted with the assistance of AI and reviewed before publication.
More from Morning Overview
- A skeleton beneath Petra’s Treasury was found clutching a chalice that resembles the Holy Grail
- 8 SUVs mechanics are quietly steering buyers away from in 2026
- Researchers pulled 8,080 pounds of invasive python from one Florida county
- A G3 solar storm could push the northern lights into 26 states tonight