Norton 360 ensures robust mobile security with antivirus features, including AI-powered malware protection, virus scanner and cleaner, and VPN for privacy. Built-in scam protection, dark web monitoring, and Wi-Fi security scanning help protect your device and accounts.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: Device security with on-device malware scanning
Not For: Users who prefer minimal telemetry on security tools
What It Means For You
Malware scanning processes the installed app list on the device; analysis of the binary found no code paths routing that list to external servers. VPN credentials and tokens are stored with hardware-backed encryption. Usage data is shared with Firebase Analytics, Adobe AEP Analytics, Avast telemetry services, and Singular for analytics and crash reporting.
Quick Verdict
Best for: Device security with on-device malware scanning
Not For: Users who prefer minimal telemetry on security tools
What It Means For You
Malware scanning processes the installed app list on the device; analysis of the binary found no code paths routing that list to external servers. VPN credentials and tokens are stored with hardware-backed encryption. Usage data is shared with Firebase Analytics, Adobe AEP Analytics, Avast telemetry services, and Singular for analytics and crash reporting.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Network Security
2 totalCode Security
7 totalPrivacy
3 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.symantec.mobilesecurity
Version
26.14.0.260729697
Analysis Date
Aug 12, 2026
Classes Analyzed
39,600
Feedback helps us improve our analysis
Build 26.14.0 delivers genuine on-device protection through malware scanning, scam call filtering, Wi-Fi threat detection, and dark web monitoring. The same build links Singular attribution and Adobe AEP Analytics, passing Norton account user ID to those services on app start based on code paths in this analysis, while the Play Store label at the time of analysis declared no third-party data sharing occurs. The build's network configuration also globally permits unencrypted HTTP for traffic outside Norton and Symantec domains, which was not runtime-tested but may affect how third-party SDK traffic travels.
Data Security - 0 findings
Network Security - 2 findings (2 medium)
Code Safety - 7 findings (1 critical, 1 high, 4 medium, 1 low)
Privacy - 3 findings (2 high, 1 low)
Third parties that may receive data from the app:
Security: 65/100
Privacy: 73/100
Observations about disclosure, each stated against the published guidance so a reader can compare:
Third-party data sharing disclosure
The Play Store data safety label at the time of analysis (retrieved August 2026) stated "No data shared with third parties." The analyzed build links Singular, Adobe AEP Analytics, Avast Burger Analytics, and Avast Shepherd Telemetry, each initialized with device or account identifiers based on code paths in this build. Google Play's developer guidance defines data sharing as transmitting user data to a third party for the third party's own purposes, with exceptions for service providers acting on the developer's behalf. Whether those flows occur in practice, and whether the developer's categorization of these SDKs falls within the service-provider exception, could not be determined from the binary alone.
Transit encryption disclosure
The Play Store data safety label at the time of analysis stated "Data is encrypted in transit." The build's network security configuration globally permits unencrypted HTTP for all traffic outside Norton and Symantec domains. Whether unencrypted connections are made at runtime could not be determined from the binary.
Authentication signing key management
The build embeds a static signing key in an assets configuration file used to generate authentication signatures for the Norton login API. Managing this key outside the app binary, for example via a server-side signing proxy or hardware-attested key issuance, would prevent it from being extracted from the build.
Financial flow access restriction
The bank account-linking activity accepts incoming navigation without verifying the triggering app's identity via Android App Links. Adding App Link verification would restrict which apps may trigger the authenticated bank account-linking flow.
Production build cleanup
The production build includes development and testing framework components that have no user-facing purpose. Excluding these from the release build would reduce unnecessary exposed surface area.
Purchase interface origin validation
The in-app purchase interface uses an unanchored domain pattern for its origin check. A fully anchored pattern would more precisely restrict which pages may interact with the purchase interface.
App Type: Mobile security and identity protection
Classes Analyzed: 39,600
Third-Party Services: 21
Context Tags: security, financial, sensitive_data, ads, contacts
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of Android applications, intended to help people make informed decisions about app security and privacy.
Developer: Gen Digital Inc.
Version: 26.14.0.260729697
Analysis Date: 2026-08-12
Package: com.symantec.mobilesecurity
Developer not yet contacted