An app that nobody updates any more does not suddenly break. It still opens, still shows the same screens, still holds the permissions you gave it. What changes is everything around it: its flaws are discovered, described, sometimes made public, and nobody fixes them any longer.
A vulnerability is exactly that: a flaw in software that someone can exploit to make it do something it should not. As long as the developer keeps releasing updates, the flaws that come to light get closed. When the updates stop, the flaws stay open, and an app forgotten in a folder becomes the weakest point of a phone that is otherwise well looked after.
This post explains that mechanism, along with the other attacks that find room in the apps you no longer use: from the app sold to a new owner to the clone that takes the original’s place. It is the threat-side companion to the recommendation on removing apps you no longer use.
One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.
The starting point
Three years ago you downloaded an app to plan a trip: maps you could use without a connection, bookings, a quick sign-in with your account on a social network. You used it for two weeks, then it ended up in a folder alongside a game, the app for an event and the app of a shop that has since closed.
The small company that built it stopped updating it. Later on, it sold the app to another business. The app is still there, with access to your location, your photos and your social media profile.
Nothing visible has happened. And that is precisely the point: forgotten apps do not ask for attention, so nobody checks what they are doing.
Why a forgotten app increases the risk
All the attacks that follow share one thing: they exploit an app that still has access to your phone, but that nobody is watching any more, neither you nor, sometimes, the people who made it.
Three characteristics set forgotten apps apart from the ones you use every day:
- They are not updated, or they are updated without you noticing. An abandoned app keeps its flaws forever; an app that changes hands can receive updates with different intentions from before.
- They keep their permissions and connections. Location, contacts, camera, access to an account: all of them remain valid until you revoke them.
- You do not look at them. If an app you use every day starts behaving oddly, you notice. If an app you have not opened in years does the same, you almost never do.
Removing the apps you do not need is not the only defence, but it is the one that takes the ground away from almost every attack described here.
1. Exploiting unpatched vulnerabilities
In plain terms. A known flaw in an old version of an app is used to reach the app’s data or the phone itself.
How it works. When a flaw is discovered, the developer usually fixes it with a security update, also called a patch (a targeted correction to the code). The fix, however, also makes the flaw better known: anyone looking for targets knows that earlier versions remain exposed. No single person is being targeted: the search is for any device, on a large scale, that still runs that version. The vehicle can be a file, a message or a web page that the faulty app handles in the wrong way.
Why an outdated app makes it more likely. A maintained app closes the flaw quickly. An abandoned app will never close it. And a forgotten app often does not even receive the updates that do exist, because automatic updates are switched off or because the app is no longer compatible with the phone’s operating system.
Possible impact. Access to the data the app holds, misuse of its permissions (location, camera, files); in the most serious cases, a foothold for installing other harmful software.
What should make you suspicious. The signs are few and faint: the app closes or freezes without warning, uses battery or data for no reason, or the store marks it as no longer available or not compatible. A last-updated date from years ago is already a clue.
How to protect yourself. Keep automatic updates on, for the system and for your apps: the reasons are explained in the recommendation on keeping your software up to date. Remove apps that have not been updated for a long time or that the store has withdrawn. If you still need one of them, look for an alternative that is actively maintained.
2. An app sold and transformed (change of ownership)
In plain terms. An app you knew and trusted passes to a new owner, who uses an update to make it do new things, and not to your advantage.
How it works. An app with many users has commercial value: whoever buys it also gains the ability to reach every phone it is installed on. In most cases the sale is entirely legitimate. In some cases, documented over the years, the new owner has added intrusive advertising, data collection or hidden features, delivered through an ordinary update.
Why a forgotten app makes it more likely. The update arrives automatically and the app keeps the permissions it had before. You never open it, so you do not notice new screens, a changed privacy notice or unfamiliar requests.
Possible impact. Personal data collected and shared with parties you do not know, aggressive advertising; occasionally, harmful software.
What should make you suspicious. The store page lists a different developer from the one you remember, an updated privacy notice arrives that you have not read, or an app you do not use starts sending advertising notifications or asking for new permissions.
How to protect yourself. Remove the apps you do not use: an app that is not there cannot be transformed. For the ones you keep, glance now and then at the developer’s name on the store page and at the permissions you have granted.
3. Invasive advertising SDKs
In plain terms. Inside an app there is code written by someone else, for instance to show adverts or measure usage, that collects more data than it needs.
How it works. Hardly any app is written from scratch. Developers use ready-made components called SDKs (Software Development Kits: packages of code that add a feature, such as advertising or usage statistics). An SDK works with the permissions of the app that hosts it: if the app can see your location, so can the SDK. Some collect data even when the app is not on screen and send it to intermediaries that combine it with other sources.
Why a forgotten app makes it more likely. An old app carries old versions of these components, sometimes with flaws of their own. And permissions granted years ago keep working, including for the code you cannot see.
Possible impact. Detailed profiling (habits, movements, interests), targeted advertising, personal data passed between companies whose names you do not even know.
What should make you suspicious. Background data or battery use (activity while the app is closed) by an app you never open, system alerts about location access while you are not using the app, adverts that seem to know where you have been.
How to protect yourself. Remove the apps you do not need; for the others, start by checking what your apps can do and allow location only while the app is in use. The concrete signs to look for are gathered in the guide to unused apps still active on your phone.
4. Breached connected accounts
In plain terms. You no longer use the app, and it may not even be on your phone, but the account you created for it still exists, with your data, and it can be breached.
How it works. Many apps ask you to register, or to sign in with an account you already have, on a social network or with your email provider. In the second case the app receives an access token: a permission that lets it read some of your account data without knowing your password. If the service behind the app suffers a breach, meaning someone gains unauthorised access to its systems, your profile data can end up in circulation, sometimes along with your password, sometimes with those very permissions. An abandoned service, with little upkeep, is often the least well protected.
Why a forgotten app makes it more likely. Uninstalling the app neither closes the account nor revokes the permission. Both stay on servers that nobody is looking after carefully any more.
Possible impact. Personal data exposed, access to part of your main account through the permission you granted, and a reused password tried on other services.
What should make you suspicious. Emails from a service you had forgotten you had, breach alerts, an unfamiliar app in the “connected apps” list of your main account.
How to protect yourself. Before uninstalling, close the account from the app or the website, after saving anything you want to keep. Every so often, review the list of apps connected to your main accounts and revoke the ones you no longer use. A different password for every service limits the damage when one of them is breached.
5. Subscription scams
In plain terms. An app charges you an expensive subscription for a minimal feature, counting on you forgetting about it.
How it works. The pattern, sometimes called fleeceware (apps that “fleece” their users), often starts with a free trial of a few days which, if it is not cancelled, turns into a weekly or yearly subscription at a disproportionate price. The app itself may be technically harmless: the damage lies in the payment that keeps repeating.
Why a forgotten app makes it more likely. The subscription does not depend on the app being installed: it carries on even after you delete it. An app you never open reminds you of nothing, and the charge slips by among your other transactions.
Possible impact. Repeated charges for months, which are not always easy to get back.
What should make you suspicious. Recurring entries with unclear names on your bank statement or in your store receipts, renewal emails from a service you do not remember signing up for.
How to protect yourself. Check the subscriptions section of the official store and cancel from there, before uninstalling. Note the end date of every free trial in your calendar.
6. Cloned apps that replace the original
In plain terms. A fake app, with a name and icon almost identical to the real one, takes its place.
How it works. When a well-known app is withdrawn from the store or stops working, people looking to reinstall it often find copies with similar names. Some come from outside the official stores: links received in a chat, websites promising the “full” or “updated” version. The clone imitates the look of the original, but it may contain aggressive advertising, data collection or malware, meaning software designed to cause harm or to spy.
Why a forgotten app makes it more likely. An old app that is no longer supported pushes you to look for a “new version” in a hurry. And anyone with many apps they do not recognise will find it harder to notice that one of them is not the original.
Possible impact. Stolen credentials (the combination of username or email and password you use to sign in), if the clone asks you to sign in with your account; personal data collected; subscriptions started without your knowledge; harmful software on the phone.
What should make you suspicious. A developer other than the one you expected, few reviews or reviews that all sound alike, permissions that do not fit what the app does, an installation offered through a link rather than through the store.
How to protect yourself. Install only from the official stores, the subject of a dedicated recommendation in the Programme. Before installing, check the developer’s name, the release date and the permissions requested. If an app has been withdrawn, look for news on the developer’s own website rather than downloading the first copy that turns up.
Summary table
| Attack | Main risk | What should make you suspicious | Effective defences |
|---|---|---|---|
| Unpatched vulnerabilities | Known flaws used to reach data and the phone | Last update years ago, sudden freezes | Automatic updates, removing abandoned apps |
| Change of ownership | Updates with new, intrusive features | Different developer, new permission requests | Fewer apps, checking the developer |
| Invasive advertising SDKs | Data collected by third-party code | Background activity, location access | Minimal permissions, fewer apps |
| Breached connected accounts | Data and permissions exposed on neglected servers | Emails from forgotten services, breach alerts | Closing the account, revoking connected apps |
| Subscription scams | Recurring charges for almost nothing | Unclear recurring entries | Cancelling through the store before uninstalling |
| Cloned apps | A fake copy in place of the original | Different developer, external links | Official stores only, checking before installing |
What they have in common
Six different attacks, three defences that cut across almost all of them:
- Fewer apps — an app that is not there cannot be exploited, sold, transformed or replaced by a clone.
- Apps kept up to date and checked — for the ones you keep: automatic updates, permissions limited to what is needed, a glance at the developer.
- Accounts and subscriptions closed, not just icons removed — because part of the risk lives outside the phone.
These are not advanced measures, and they cover most real-world cases. To put them into practice, in a clear order and with a routine you can repeat, see the guide on how to clean up your apps.
Protection checklist
- ☐ Automatic updates are on for the system and for apps
- ☐ No app that has gone years without an update or that the store has withdrawn
- ☐ Apps not opened for three months have been reviewed and removed if not needed
- ☐ Data is saved and accounts are closed before uninstalling
- ☐ Subscriptions are cancelled from the store’s subscriptions section, not just by deleting the app
- ☐ The list of apps connected to your main accounts has been reviewed and cleared out
- ☐ Location, contacts and camera are granted only to apps that genuinely need them
- ☐ New apps are installed only from the official stores, after checking the developer and the permissions
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that a forgotten app is not inert: it keeps permissions, accounts and flaws that someone else can use |
| Skills | Recognising the mechanism of each attack from its signals, from the last-updated date to the developer’s name |
| Secure Behaviour | Keeping only the apps you need, up to date, and closing accounts and subscriptions before uninstalling |
Reference level: FL3 — Autonomous, with elements of FL2 — Beginner in the sections on updates and subscriptions.
Conclusion
The attacks described here are rarely aimed at you in particular. They work at scale, and they find room where nobody is looking: in the apps you stopped using but never removed.
That is why the most effective defence is also the simplest: keep only the apps you use, keep them up to date, and close whatever you leave behind. There is no need to give up on apps; each one simply needs a reason to stay.
To see where to start, the digital resilience self-assessment helps you take stock.
Something to think about. Of the apps on your phone, how many could you say who updates them today, and when they last did so?
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- Fleeceware: Apps That Charge You for Almost Nothing — how to spot and cancel disproportionate subscriptions
- Check App Details: The Filter Before You Install — the filter that keeps clones and transformed apps at a distance
- Review Installed Apps: The Twenty-Minute Clear-Out — a quick review of your app list
Related content
- Removing apps you no longer use — the recommendation this belongs to
- Unused apps still active on your phone — the indicators these attacks leave behind
- How to clean up your apps — the steps to fix and prevent
- Tools for managing apps — the technologies that make them less effective
- Consequences of forgotten apps — what they lead to when they succeed
- Risks of abandoned apps — what is affected: the confidentiality, integrity and availability of your data
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



