Mozilla VPN - Secure & Private Security & Privacy Scorecard

Android

89
Overall trust score
Trustworthy
88
Security
92
Privacy

Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.

Best for

General use with standard privacy expectations

Findings

  • 0 critical
  • 0 high
  • 1 medium
  • 3 low
  • 3 info

1 issue identified across security and privacy analysis.

Top security issues

  • EncryptedSharedPreferences Silent Plaintext Fallback Exposes WireGuard Private Key
  • GleanDebugActivity Exported Without Permission Gate in Production Build
  • Qt Test Framework and QML TCP Debugger Plugins Bundled in Production Binary

Top privacy issues

  • GleanDebugActivity Can Force-Send Telemetry to Public Server Bypassing User Opt-Out
  • Android Install Referrer SDK Present — No App-Layer Usage Confirmed
  • Mozilla Glean Telemetry Collects Session UUIDs Enabling Long-Term Session Correlation

Full analysis

<!-- TRUSTEDVERDICTHEADER -->

Under review

We could not verify enough to decide, so this app is held for review.

Trust Pillars

  • Secure by Design: Strong. Meets a high bar in this area.
  • Data Respect: Under review. We could not fully verify this area yet.
  • Honest Experience: Strong. Meets a high bar in this area.
  • User Control: Strong. Meets a high bar in this area.
  • Child-Safe: Not applicable. Does not apply to this app.

<!-- /TRUSTEDVERDICTHEADER -->

Security & Privacy Scorecard

org.mozilla.firefox.vpn

What This Means for You

Usage data and device activity may be shared with the app developer and the services it integrates with. The category summary below shows the scope so people can decide whether it fits their needs.

Recommendation: Trustworthy

This app generally follows good security and privacy practices.

Best For: Privacy-conscious users who want a no-ads, no-tracker VPN with strong cryptographic defaults

Avoid If: Users on rooted devices where a silent Keystore failure could expose VPN private keys in plaintext

Key Findings

Data Security: 1 finding (1 medium)

Network Security: 0 findings

Code Safety: 0 findings

Privacy: 1 finding (1 info)

Privacy Concerns

What Data is Collected

Review the app's store listing and in-app privacy notices for a full data collection disclosure.

Third-Party Data Sharing

The following third parties may receive user data:

  • Mozilla Glean
  • WireGuard-Go
  • Google Play Billing
  • Google Play Services
  • Google Tink
  • Firebase DataTransport
  • Android Install Referrer
  • BouncyCastle
  • JNA (Java Native Access)
  • AndroidX Security Crypto
  • WorkManager
  • Qt 6

Understanding the Scores

Security: 88/100
Privacy: 92/100

Security Breakdown

  • Data Security: 83/100. How the app handles stored data.
  • Network Security: 95/100. How the app handles data in transit.
  • Code Safety: 90/100. Overall code hygiene signals.

Privacy Breakdown

  • Data Collection: 95/100. Scope of data collected.
  • Data Sharing: 100/100. Third-party data sharing behavior.
  • User Control: 40/100. Controls the app offers over personal data.

Positive Security Features

  • Sensitive data is encrypted with AES256-GCM backed by the Android Keystore as the primary storage path
  • App backup is disabled, preventing ADB or cloud backup exfiltration of VPN credentials
  • VPN tunnel uses FIPS 140-3 verified cryptography (Curve25519, ChaCha20-Poly1305, BLAKE2s)
  • No WebView used — entire JavaScript injection surface is eliminated; OAuth and payments open in the system browser
  • VPN daemon is protected by a system-level signature permission no third-party app can hold
  • No hardcoded secrets, API keys, or server-side credentials found anywhere in the build
  • No third-party ad, analytics, or crash-reporting SDKs — only Mozilla's own opt-in telemetry
  • Telemetry is opt-in by default and collects no PII such as IP addresses, destinations, or browsing history

Areas for Improvement

  • Review the category summary above for where the app could strengthen its practices.
  • Keep the app updated to receive the latest security improvements from the developer.

About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

App Details

Developer: Unknown developer
Version: 2.36.0 (build 17763577)
Analysis Date: 2026-07-11
Package: org.mozilla.firefox.vpn

Versions & scan history

ScanDateOverall score
#3 (current) 89/100
#2 52/100