Professional networking platform for career discovery, job search, and professional connections.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: Professionals managing career and networking
What It Means For You
No Meta Audience Network or Google AdMob SDK is bundled in this build; LinkedIn's advertising operates through its own infrastructure rather than external consumer ad networks. Usage, device, and attribution data flows to Singular, Apple AdServices, and Firebase Crashlytics. Qualtrics XM is also integrated for in-app surveys.
Quick Verdict
Best for: Professionals managing career and networking
What It Means For You
No Meta Audience Network or Google AdMob SDK is bundled in this build; LinkedIn's advertising operates through its own infrastructure rather than external consumer ad networks. Usage, device, and attribution data flows to Singular, Apple AdServices, and Firebase Crashlytics. Qualtrics XM is also integrated for in-app surveys.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Network Security
3 totalCode Security
3 totalPrivacy
1 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.linkedin.LinkedIn
Version
2026.0805.1140 (Build 9.32.2755)
Analysis Date
Aug 13, 2026
Classes Analyzed
12
Feedback helps us improve our analysis
CITT assesses this build Trustworthy for professional users. The binary links strong encryption for all LinkedIn API traffic, stores login credentials in the most secure iOS Keychain protection class, and implements Apple App Attest for server-side integrity verification. Contact data sharing for connection suggestions is disclosed in the permission request, and users who decline the contact permission are not affected by that disclosure.
Data Security: 0 findings
Network Security: 3 findings (3 medium)
Code Safety: 3 findings (3 low)
Privacy: 1 finding (1 low)
No sensitive data was identified as processed only on the device.
Third parties that may receive data from the app:
Security: 84/100
Privacy: 86/100
Observations about disclosure, each stated against the published guidance so a reader can compare:
Transport Security Scope
Apple's App Transport Security documentation recommends scoping any exceptions to the specific domains that require them. Info.plist in this build sets a global unrestricted transport configuration with no per-domain exceptions, removing enforcement across the entire app including in-app browser flows. Whether server-side redirect controls or other mitigations compensate for this was not tested.
Contact Field Breadth
The permission request in this build states that contacts are uploaded to LinkedIn's servers for connection suggestions. The binary links contact field keys for postal addresses, social profiles, and instant-message handles beyond name, email, and phone. Whether this extended scope is reflected in the App Store privacy label could not be determined from the binary alone.
App Privacy Manifest
Apple's guidance recommends including an app privacy manifest to document data types and system API usage. The main binary in this build does not include one. Adding it could make the App Store privacy label more complete. This is an optional enhancement.
Per-Domain Transport Security Scoping
Adding per-domain exception entries for the specific third-party services that require unencrypted connections would reduce the surface area for content injection into in-app browser flows.
Origin Validation for In-App Browser Message Handlers
The identity-verification in-app browser in this build processes JavaScript messages from third-party providers. Adding validation of the originating page's security origin before dispatching those messages would reduce the risk of injected content triggering internal navigation.
App Type: Professional networking - high sensitivity (contacts, identity verification, career data)
Classes Analyzed: 12
Third-Party Services: 20
Context Tags: social, contacts, ads, sensitive_data, camera
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of iOS applications, intended to help people make informed decisions about app security and privacy.
Developer: LinkedIn Corporation
Version: 2026.0805.1140 (Build 9.32.2755)
Analysis Date: 2026-08-13
Package: com.linkedin.LinkedIn
Developer not yet contacted