19 Sources
[1]
DeepSeek's app contains serious privacy and security vulnerabilities that you should know about
Tech fans who flocked to try out DeepSeek will want to think twice about what the app is doing - just days after vulnerabilities were found in the iOS app, a research team at Security Scorecard has found similar privacy concerns in the Android app as well. Despite the app's rise in popularity
[2]
DeepSeek iOS App Disables Apple's Defenses, Sends Data to TikTok Parent
The security assessment by NowSecure highlights glaring weaknesses in the app's security standards for iOS users. DeepSeek has grabbed the spotlight in the AI industry as the underdog that briefly became the world's leading app, overtaking ChatGPT AI assistant. While many see it as the Robinhood
[3]
DeepSeek Is Sending Unencrypted Data To Chinese Servers, As Its iOS App Suffers From Multiple Severe Security Flaws
DeepSeek app topped the App Store charts as it was the most downloaded AI app, even beating ChatGPT in its first month of release. However, the app has raised various concerns since its arrival, which include privacy and security. It has now been discovered that DeepSeek has been sending
[4]
DeepSeek App Transmits Sensitive User and Device Data Without Encryption
A new audit of DeepSeek's mobile app for the Apple iOS operating system has found glaring security issues, the foremost being that it sends sensitive data over the internet sans any encryption, exposing it to interception and manipulation attacks. The assessment comes from NowSecure, which also
[5]
Security flaws and privacy concerns plague DeepSeek iOS app
It's one of the biggest apps in the App Store. However, it looks like DeepSeek is also riddled with security flaws. According to NowSecure, the Chinese-based AI chatbot has significant data security and storage flaws. The app, which launched to considerable attention last month, reportedly
[6]
DeepSeek's iOS app sends unencrypted data to Chinese servers
Chart-topping AI iPhone app DeepSeek has been found to be sending data to Chinese-owned services, as well as collecting extensive user data that is held and sent unencrypted. DeepSeek is a generative AI app, similar to ChatGPT, which launched in January 2025 and practically immediately went to the
[7]
Multiple security flaws found in DeepSeek iOS app
The latest findings are far worse than the previous security failure which exposed chat history and other sensitive information in a database requiring no authentication ... While we'd mentioned it before it made headlines, for most people DeepSeek came out of nowhere and overnight became the most
[8]
The DeepSeek App Doesn't Send or Store Data Securely: Here's What Researchers Found
If you're interested in AI, there's a good chance you've heard of DeepSeek, the AI model that recently made waves in the tech scene. While people downloaded the app in droves, it turns out it has some nasty privacy issues. DeepSeek Fails to Properly Encrypt Traffic of Securely Store Login Data As
[9]
DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers
A little over two weeks ago, a largely unknown China-based company named DeepSeek stunned the AI world with the release of an open source AI chatbot that had simulated reasoning capabilities that were largely on par with those from market leader OpenAI. Within days, the DeepSeek AI assistant app
[10]
DeepSeek Might Be Sharing Your Data With This Banned Chinese Company
DeepSeek source code reportedly contains evidence that links the popular artificial intelligence (AI) chatbot with a Chinese telecommunication provider that was banned in the US. According to a report, a cybersecurity firm has uncovered code that could be used to send data entered on DeepSeek's web
[11]
DeepSeek coding has the capability to transfer users' data directly to the Chinese government
The app developed its AI model for way less money than its American competitors. DeepSeek, the explosive new artificial intelligence, tool that took the world by storm, has code hidden in its programming which has the built-in capability to send user data directly to the Chinese government,
[12]
China's DeepSeek web version is raising security alarms. Here's why
The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from operating in the United
[13]
DeepSeek's Secret Code: Data Going to China?
After TikTok, will DeepSeek be the next Chinese company to be banned by the US? According to security researchers, code found on the website of Chinese AI company DeepSeek has the capability of sending login information from a user to China Mobile. China Mobile is a state-owned telecommunications
[14]
DeepSeek chatbot linked to China's telecom firm that is barred from operating in United States, claim researchers
DeepSeek in its privacy policy acknowledged storing data on servers inside the People's Republic of China.The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login
[15]
Researchers say China's DeepSeek chatbot is linked to state telecom, raising data privacy concerns
The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from operating in the United
[16]
Researchers say China's DeepSeek chatbot is linked to state telecom, raising data privacy concerns
WASHINGTON (AP) -- The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from
[17]
Researchers say China's DeepSeek chatbot is linked to state telecom, raising data privacy concerns
WASHINGTON (AP) -- The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from
[18]
Researchers say China's DeepSeek chatbot is linked to state telecom, raising data privacy concerns
WASHINGTON (AP) -- The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from
[19]
China's DeepSeek chatbot ties to state telecom spark privacy fears
WASHINGTON -- The website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from operating
Share
Copy Link
Multiple security audits reveal significant vulnerabilities in DeepSeek's iOS and Android apps, including unencrypted data transmission to Chinese servers and poor security practices, raising concerns about user privacy and data protection.

DeepSeek, an AI chatbot app that briefly surpassed ChatGPT in popularity, has come under scrutiny for significant security and privacy issues. The app, which topped download charts on both iOS and Android platforms, is now facing serious questions about its data handling practices and potential risks to user information
1
.Security audits conducted by NowSecure and Security Scorecard have revealed alarming vulnerabilities in both the iOS and Android versions of the DeepSeek app. Key findings include:
Unencrypted Data Transmission: The app sends user data over the internet without proper encryption, exposing it to potential interception and manipulation
2
.Disabled Security Features: DeepSeek's iOS app globally disables Apple's App Transport Security (ATS), a crucial protection mechanism
3
.Outdated Encryption Methods: The app utilizes the 3DES algorithm, now considered an insecure form of encryption
2
.Hardcoded Keys and Weak Cryptography: Security Scorecard identified issues such as hardcoded keys and vulnerabilities to SQL injection attacks
1
.DeepSeek's privacy policy reveals extensive data collection practices, including:
1
A major concern is the transmission of user data to servers controlled by ByteDance, the parent company of TikTok. This raises potential compliance issues with GDPR, CCPA, and national security laws
4
. The app's website has also been found to send user login information to China Mobile, a state-owned telecommunications company banned from operating in the United States4
.Related Stories
In response to these security concerns, several countries and government agencies have taken action:
4
Security experts recommend deleting the DeepSeek app from managed and BYOD environments until these issues are addressed
5
. Organizations are advised to consider alternative AI chatbot solutions that prioritize mobile app security and data protection.As DeepSeek faces scrutiny similar to TikTok, it may need to address these security and privacy concerns promptly to avoid potential bans or forced sales in certain markets
3
. The situation highlights the growing importance of data security and privacy in AI applications, especially those with international reach and potential geopolitical implications.Summarized by
Navi
[1]
[5]
1
Science and Research

2
Technology

3
Policy and Regulation
