1 Static Analysis of The DeepSeek Android App
stacihdy729285 edited this page 6 months ago


I conducted a static analysis of DeepSeek, a Chinese LLM chatbot, utilizing version 1.8.0 from the Google Play Store. The goal was to recognize prospective security and personal privacy issues.

I've discussed DeepSeek previously here.

Additional security and personal privacy concerns about DeepSeek have actually been raised.

See likewise this analysis by NowSecure of the iPhone version of DeepSeek

The findings detailed in this report are based simply on fixed analysis. This means that while the code exists within the app, there is no conclusive evidence that all of it is performed in practice. Nonetheless, the existence of such code warrants analysis, specifically provided the growing concerns around information privacy, security, the possible abuse of AI-driven applications, and cyber-espionage dynamics between worldwide powers.

Key Findings

Suspicious Data Handling & Exfiltration

- Hardcoded URLs direct information to external servers, raising concerns about user activity monitoring, such as to ByteDance "volce.com" endpoints. NowSecure determines these in the iPhone app the other day too. - Bespoke file encryption and data obfuscation approaches are present, with signs that they could be utilized to exfiltrate user .