Chase Mobile Security & Privacy Scorecard

Android

38
Overall trust score
Unsafe
35
Security
40
Privacy

In-app behavior is recorded by QuantumMetric and device activity is shared with Adobe for ad targeting. Bugsnag receives crash data from user sessions. Location is processed via Google when users use branch or ATM finders.

Best for

Existing Chase customers managing accounts on the go

Avoid if

You prefer not to share behavioral data with third parties

Findings

  • 3 critical
  • 6 high
  • 2 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Universal File Access in Non-Shared WebView Container
  • Unencrypted Room Databases Store Financial Data
  • Session Cookies Synced to WebView

Top privacy issues

  • QuantumMetric Session Replay Captures Financial Data
  • Analytics Tracking of Financial User Behavior
  • Bugsnag Crash Reports May Leak Sensitive Data

Full analysis

Chase Mobile

Version: 4.712 | Analyzed: 2026-02-05

What This Means for You

In-app behavior is recorded by QuantumMetric and device activity is shared with Adobe for ad targeting. Bugsnag receives crash data from user sessions. Location is processed via Google when users use branch or ATM finders.

Recommendation: Use With Caution

Best For: Existing Chase customers managing accounts on the go
Avoid If: You prefer not to share behavioral data with third parties

Key Findings

Data Security - 2 findings (1 critical, 1 high)

Network Security - 2 findings (1 critical, 1 high)

Code Safety - 0 findings

Privacy - 4 findings (1 critical, 2 high, 1 medium)

Privacy Concerns

What Data is Collected

The app collects behavioral and session data from user interactions, crash reports from user sessions, and location data when users use branch or ATM finder features. Device identifiers and usage patterns are also gathered to support analytics and fraud detection functions.

Third-Party Data Sharing

User data is shared with multiple third-party companies:

  • QuantumMetric - records in-app behavior and session activity
  • Adobe Demdex - receives device activity for advertising targeting
  • Bugsnag - receives crash data and diagnostic information from user sessions
  • Zimperium - processes device security signals for fraud detection
  • Google Maps API / Google Places API - processes location when users use branch or ATM finders
  • Split.io - receives usage data to support feature testing and rollouts

Understanding the Scores

Category Score
Security 35/100
Privacy 40/100
Data Security 25/100
Network Security 50/100
Code Safety 45/100
Data Collection 50/100
Data Sharing 35/100
User Control 60/100

Positive Security Features

  • No specific positive security practices were identified in this analysis.

Areas for Improvement

  • Data transmitted during user sessions travels with less protection than expected, which means financial information may not be fully protected under certain network conditions.
  • Behavioral and session data is distributed to a broad range of advertising and analytics companies. Reducing the scope of third-party data sharing would better protect user privacy.
  • Sensitive information stored on the device is not handled according to current best practices, creating additional risk if the device is accessed by someone else.

About This Analysis

This scorecard reflects analysis of the app's code and observed behaviors as of the scan date above. Results represent a point-in-time assessment and may not capture all behaviors.

App Details

  • App: Chase Mobile
  • Package: com.chase.sig.android
  • Version: 4.712
  • Platform: Android
  • Scan Date: 2026-02-05

Versions & scan history

ScanDateOverall score
#1 (current) 38/100