I did a static analysis on the DeepSeek Android app

tl;dr it does aggressive device fingerprinting, root detection, has anti-tampering mechanisms, bundles native code and has dynamic code loading and execution facilities

none of which should be necessary for an app like this

more here: michael.bacarella.com/2025/02/

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/mbacarella/statuses/113964200447544688 on your instance and quote it. (Note that quoting is not supported in Mastodon.)