Mozilla VPN - Secure & Private Security & Privacy Scorecard
Android
Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.
Best for
General use with standard privacy expectations
Findings
- 0 critical
- 0 high
- 1 medium
- 3 low
- 3 info
1 issue identified across security and privacy analysis.
Top security issues
- EncryptedSharedPreferences Silent Plaintext Fallback Exposes WireGuard Private Key
- GleanDebugActivity Exported Without Permission Gate in Production Build
- Qt Test Framework and QML TCP Debugger Plugins Bundled in Production Binary
Top privacy issues
- GleanDebugActivity Can Force-Send Telemetry to Public Server Bypassing User Opt-Out
- Android Install Referrer SDK Present — No App-Layer Usage Confirmed
- Mozilla Glean Telemetry Collects Session UUIDs Enabling Long-Term Session Correlation
Full analysis
<!-- TRUSTEDVERDICTHEADER -->
Under review
We could not verify enough to decide, so this app is held for review.
Trust Pillars
- Secure by Design: Strong. Meets a high bar in this area.
- Data Respect: Under review. We could not fully verify this area yet.
- Honest Experience: Strong. Meets a high bar in this area.
- User Control: Strong. Meets a high bar in this area.
- Child-Safe: Not applicable. Does not apply to this app.
<!-- /TRUSTEDVERDICTHEADER -->
Security & Privacy Scorecard
org.mozilla.firefox.vpn
What This Means for You
Usage data and device activity may be shared with the app developer and the services it integrates with. The category summary below shows the scope so people can decide whether it fits their needs.
Recommendation: Trustworthy
This app generally follows good security and privacy practices.
Best For: Privacy-conscious users who want a no-ads, no-tracker VPN with strong cryptographic defaults
Avoid If: Users on rooted devices where a silent Keystore failure could expose VPN private keys in plaintext
Key Findings
Data Security: 1 finding (1 medium)
Network Security: 0 findings
Code Safety: 0 findings
Privacy: 1 finding (1 info)
Privacy Concerns
What Data is Collected
Review the app's store listing and in-app privacy notices for a full data collection disclosure.
Third-Party Data Sharing
The following third parties may receive user data:
- Mozilla Glean
- WireGuard-Go
- Google Play Billing
- Google Play Services
- Google Tink
- Firebase DataTransport
- Android Install Referrer
- BouncyCastle
- JNA (Java Native Access)
- AndroidX Security Crypto
- WorkManager
- Qt 6
Understanding the Scores
Security: 88/100
Privacy: 92/100
Security Breakdown
- Data Security: 83/100. How the app handles stored data.
- Network Security: 95/100. How the app handles data in transit.
- Code Safety: 90/100. Overall code hygiene signals.
Privacy Breakdown
- Data Collection: 95/100. Scope of data collected.
- Data Sharing: 100/100. Third-party data sharing behavior.
- User Control: 40/100. Controls the app offers over personal data.
Positive Security Features
- Sensitive data is encrypted with AES256-GCM backed by the Android Keystore as the primary storage path
- App backup is disabled, preventing ADB or cloud backup exfiltration of VPN credentials
- VPN tunnel uses FIPS 140-3 verified cryptography (Curve25519, ChaCha20-Poly1305, BLAKE2s)
- No WebView used — entire JavaScript injection surface is eliminated; OAuth and payments open in the system browser
- VPN daemon is protected by a system-level signature permission no third-party app can hold
- No hardcoded secrets, API keys, or server-side credentials found anywhere in the build
- No third-party ad, analytics, or crash-reporting SDKs — only Mozilla's own opt-in telemetry
- Telemetry is opt-in by default and collects no PII such as IP addresses, destinations, or browsing history
Areas for Improvement
- Review the category summary above for where the app could strengthen its practices.
- Keep the app updated to receive the latest security improvements from the developer.
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.
App Details
Developer: Unknown developer
Version: 2.36.0 (build 17763577)
Analysis Date: 2026-07-11
Package: org.mozilla.firefox.vpn
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 89/100 | |
| #2 | 52/100 |