
But the company’s Android app, which offers not only search capabilities but also acts as an AI assistant, is riddled with a host of security issues that could expose its users to data theft, account takeovers and impersonation attacks from malicious hackers, according to a report by India-based mobile security company Appknox. One of these gaps also lets anyone access Perplexity’s API for free, exposing the company itself to the risk of losing revenue.
Security researcher and Appknox CEO Subho Halder said it’s easy to make clones of Perplexity’s Android app because its code is embedded with what’s called “hardcoded secrets” — sensitive information like passwords and API keys (a string of alphabets and numbers that is used to identify and verify an application making requests to use that API), which can be extracted by an attacker. The cloned app can then be used to trick users into believing it’s the real one, enabling hacks to collect private data like login information and uploaded documents.
Perplexity rolled out its agent-like AI assistant for Android devices in January, which it claimed could carry out tasks like booking an Uber, playing a video on YouTube, finding songs on Spotify and making reservations all on its own. But the slew of security flaws has been uncovered just as Perplexity, reportedly in talks to raise funding at an $18 billion valuation, tries to find new ways to distribute its mobile app to more users and put it in more people’s hands. The company is in talks with smartphone manufacturing giant Samsung to integrate its AI assistant into their phones and it has already reached an agreement with Lenovo-owned Motorola to do the same, according to Bloomberg. Perplexity did not respond to a request for comment.
Perplexity’s app is also susceptible to an attack called “task hijacking” in which a rogue app takes control of the phone’s actions without your knowledge as you use a different one. The now-malicious app can then monitor your activity and collect data. For example, someone could hack Perplexity’s app so that if you’re typing a prompt into Amazon’s search box, it could unknowingly give hackers access to it. Halder said it could even fall prey to network-based attacks where people on an unsecured network such as an airport hotspot can have their conversations with Perplexity intercepted and their data stolen.
Founded in 2022, Perplexity’s first product was a conversational AI search engine that crawls the web for information and uses a mix of large language models from OpenAI, Anthropic and Meta to answer questions on any given topic by producing AI-generated summaries that include links to sources from across the web. It has raised a total of $900 million in venture funding from tech bigwigs like Amazon founder Jeff Bezos and OpenAI cofounder Andrej Karpathy and is currently valued at $9 billion, according to Pitchdeck. Perplexity’s app has more than 10 million downloads on Google Play.
Security vulnerabilities are just part of the problem for Perplexity. The company has come under fire from Forbes and other media outlets for allegedly plagiarizing their reporting and redistributing it across multiple platforms through a feature called Perplexity Pages. At the time, Srinivas said that its republishing product feature had “rough edges” and that Perplexity was “improving it with more feedback.” In June 2024, Forbes sent a cease-and-desist letter to Perplexity, accusing it of infringing copyright, to which the Perplexity responded saying the claims were meritless and that factual information is not protected by copyright law.
Safety in the world of AI often focuses on the models themselves–ensuring that they’re producing accurate information and aren’t affected by bias. This report underscores the idea that securing the application where people interact with the models is just as important, Halder told Forbes.
Halder’s advice to users is to remove Perplexity’s Android app from the phone until the issues are resolved. AI applications are being built at a breakneck speed and many are failing on the most basic vulnerability checks, Halder said, but “Perplexity is a full-blown security hazard.”
MORE FROM FORBES
ForbesThis Tech Incubator Is Harder To Get Into Than HarvardBy Richard NievaForbesThis AI Founder Has Unseated Taylor Swift As The World’s Youngest Self-Made Woman BillionaireBy Kerry A. DolanForbesNew Data Shows Just How Badly OpenAI And Perplexity Are Screwing Over PublishersBy Rashi ShrivastavaForbesBuzzy AI Search Engine Perplexity Is Directly Ripping Off Content From News OutletsBy Sarah EmersonThe above is the detailed content of Perplexity's Android App Is Infested With Security Flaws, Report Finds. For more information, please follow other related articles on the PHP Chinese website!
How to Run LLM Locally Using LM Studio? - Analytics VidhyaApr 19, 2025 am 11:38 AMRunning large language models at home with ease: LM Studio User Guide In recent years, advances in software and hardware have made it possible to run large language models (LLMs) on personal computers. LM Studio is an excellent tool to make this process easy and convenient. This article will dive into how to run LLM locally using LM Studio, covering key steps, potential challenges, and the benefits of having LLM locally. Whether you are a tech enthusiast or are curious about the latest AI technologies, this guide will provide valuable insights and practical tips. Let's get started! Overview Understand the basic requirements for running LLM locally. Set up LM Studi on your computer
Guy Peri Helps Flavor McCormick's Future Through Data TransformationApr 19, 2025 am 11:35 AMGuy Peri is McCormick’s Chief Information and Digital Officer. Though only seven months into his role, Peri is rapidly advancing a comprehensive transformation of the company’s digital capabilities. His career-long focus on data and analytics informs
What is the Chain of Emotion in Prompt Engineering? - Analytics VidhyaApr 19, 2025 am 11:33 AMIntroduction Artificial intelligence (AI) is evolving to understand not just words, but also emotions, responding with a human touch. This sophisticated interaction is crucial in the rapidly advancing field of AI and natural language processing. Th
12 Best AI Tools for Data Science Workflow - Analytics VidhyaApr 19, 2025 am 11:31 AMIntroduction In today's data-centric world, leveraging advanced AI technologies is crucial for businesses seeking a competitive edge and enhanced efficiency. A range of powerful tools empowers data scientists, analysts, and developers to build, depl
AV Byte: OpenAI's GPT-4o Mini and Other AI InnovationsApr 19, 2025 am 11:30 AMThis week's AI landscape exploded with groundbreaking releases from industry giants like OpenAI, Mistral AI, NVIDIA, DeepSeek, and Hugging Face. These new models promise increased power, affordability, and accessibility, fueled by advancements in tr
Perplexity's Android App Is Infested With Security Flaws, Report FindsApr 19, 2025 am 11:24 AMBut the company’s Android app, which offers not only search capabilities but also acts as an AI assistant, is riddled with a host of security issues that could expose its users to data theft, account takeovers and impersonation attacks from malicious
Everyone's Getting Better At Using AI: Thoughts On Vibe CodingApr 19, 2025 am 11:17 AMYou can look at what’s happening in conferences and at trade shows. You can ask engineers what they’re doing, or consult with a CEO. Everywhere you look, things are changing at breakneck speed. Engineers, and Non-Engineers What’s the difference be
Rocket Launch Simulation and Analysis using RocketPy - Analytics VidhyaApr 19, 2025 am 11:12 AMSimulate Rocket Launches with RocketPy: A Comprehensive Guide This article guides you through simulating high-power rocket launches using RocketPy, a powerful Python library. We'll cover everything from defining rocket components to analyzing simula


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

PhpStorm Mac version
The latest (2018.2.1) professional PHP integrated development tool

SublimeText3 Mac version
God-level code editing software (SublimeText3)

SAP NetWeaver Server Adapter for Eclipse
Integrate Eclipse with SAP NetWeaver application server.

EditPlus Chinese cracked version
Small size, syntax highlighting, does not support code prompt function

DVWA
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is very vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, to help web developers better understand the process of securing web applications, and to help teachers/students teach/learn in a classroom environment Web application security. The goal of DVWA is to practice some of the most common web vulnerabilities through a simple and straightforward interface, with varying degrees of difficulty. Please note that this software






