Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps and found that nearly three in four contained software dependencies associated with documented vulnerabilities.
The team built its dataset from AndroZoo, a large archive of Android apps, then filtered for companion apps tied to IoT devices.
“Consequently, many users are left relying on unmaintained or delisted applications to manage sensitive IoT data, significantly broadening their security exposure,” they added.
They interpreted this finding as a sign that outdated cryptography is a habit throughout the IoT app ecosystem generally, not something specific to abandonment.
Deprecated cryptography was more common in the active group, appearing in 17% of those apps compared with 8.4% of abandoned apps.