Chase Mobile Security & Privacy Scorecard
Android
In-app behavior is recorded by QuantumMetric and device activity is shared with Adobe for ad targeting. Bugsnag receives crash data from user sessions. Location is processed via Google when users use branch or ATM finders.
Best for
Existing Chase customers managing accounts on the go
Avoid if
You prefer not to share behavioral data with third parties
Findings
- 3 critical
- 6 high
- 2 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Universal File Access in Non-Shared WebView Container
- Unencrypted Room Databases Store Financial Data
- Session Cookies Synced to WebView
Top privacy issues
- QuantumMetric Session Replay Captures Financial Data
- Analytics Tracking of Financial User Behavior
- Bugsnag Crash Reports May Leak Sensitive Data
Full analysis
Chase Mobile
Version: 4.712 | Analyzed: 2026-02-05
What This Means for You
In-app behavior is recorded by QuantumMetric and device activity is shared with Adobe for ad targeting. Bugsnag receives crash data from user sessions. Location is processed via Google when users use branch or ATM finders.
Recommendation: Use With Caution
Best For: Existing Chase customers managing accounts on the go
Avoid If: You prefer not to share behavioral data with third parties
Key Findings
Data Security - 2 findings (1 critical, 1 high)
Network Security - 2 findings (1 critical, 1 high)
Code Safety - 0 findings
Privacy - 4 findings (1 critical, 2 high, 1 medium)
Privacy Concerns
What Data is Collected
The app collects behavioral and session data from user interactions, crash reports from user sessions, and location data when users use branch or ATM finder features. Device identifiers and usage patterns are also gathered to support analytics and fraud detection functions.
Third-Party Data Sharing
User data is shared with multiple third-party companies:
- QuantumMetric - records in-app behavior and session activity
- Adobe Demdex - receives device activity for advertising targeting
- Bugsnag - receives crash data and diagnostic information from user sessions
- Zimperium - processes device security signals for fraud detection
- Google Maps API / Google Places API - processes location when users use branch or ATM finders
- Split.io - receives usage data to support feature testing and rollouts
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 40/100 |
| Data Security | 25/100 |
| Network Security | 50/100 |
| Code Safety | 45/100 |
| Data Collection | 50/100 |
| Data Sharing | 35/100 |
| User Control | 60/100 |
Positive Security Features
- No specific positive security practices were identified in this analysis.
Areas for Improvement
- Data transmitted during user sessions travels with less protection than expected, which means financial information may not be fully protected under certain network conditions.
- Behavioral and session data is distributed to a broad range of advertising and analytics companies. Reducing the scope of third-party data sharing would better protect user privacy.
- Sensitive information stored on the device is not handled according to current best practices, creating additional risk if the device is accessed by someone else.
About This Analysis
This scorecard reflects analysis of the app's code and observed behaviors as of the scan date above. Results represent a point-in-time assessment and may not capture all behaviors.
App Details
- App: Chase Mobile
- Package: com.chase.sig.android
- Version: 4.712
- Platform: Android
- Scan Date: 2026-02-05
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 38/100 |