US Military Apps Found to Contain Foreign Code from Adversary Nations
A new security study released this week revealed that more than 12 % of mobile applications developed for U.S. military personnel contain code originating from foreign vendors, including companies based in countries the Pentagon lists as adversaries. The analysis, conducted by a coalition of defense technology researchers, examined thousands of apps used by service members for logistics, training, and communication, uncovering embedded libraries and dependencies that trace back to external suppliers.
The findings highlight a growing concern about supply‑chain vulnerabilities in defense software. While many of the identified foreign components are common open‑source libraries, a subset originates from firms in nations such as Russia, China, and Iran—countries the U.S. government has designated as hostile. The presence of these elements could potentially allow adversaries to insert malicious code or create back‑doors, raising questions about the adequacy of current vetting and monitoring processes for defense‑grade applications.
In response, the Department of Defense has announced plans to tighten its software acquisition guidelines and to expand its internal code‑review protocols. Officials say the goal is to ensure that all applications used by service members meet stringent security standards and are free from foreign code that could compromise operational integrity.