I broke AppLovin's mediation cipher protocol
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A researcher has decrypted AppLovin’s ad mediation encryption, exposing how device data can deterministically identify iPhones across apps, even with ATT disabled. This raises privacy concerns about user tracking.

A researcher has decrypted AppLovin’s proprietary encryption protocol used in its ad mediation requests, revealing that detailed device data can be used to re-identify iPhone users across different apps, even when they have denied App Tracking Transparency (ATT). This undermines assumptions that ATT is the sole method for user identification and raises privacy concerns.

The researcher analyzed thousands of encrypted bid requests sent by AppLovin’s SDK, uncovering that each request contains a payload encrypted with a cipher built from a shared SDK key and a constant salt embedded in the SDK binary. The encryption uses a non-cryptographically secure pseudorandom number generator (SplitMix64), and the cipher does not include authentication, allowing potential tampering.

Decryption of these requests revealed a JSON payload containing extensive device information, including hardware identifiers, OS details, screen metrics, and other system properties. Notably, even when the user denies ATT and IDFA is zeroed, the payload still includes device-specific fingerprint data, enabling deterministic re-identification across apps and ad networks.

Why It Matters

This development challenges the common belief that ATT is the only barrier to user tracking on iOS devices. By exposing the encryption’s vulnerabilities and the detailed device data transmitted, it suggests that app developers and ad networks can still track users across apps without relying on identifiers like IDFA. This has privacy implications, potentially undermining user control over data sharing and consent.

Amazon

iPhone privacy screen protector

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

AppLovin is a major player in mobile ad mediation, integrating multiple ad networks and demand partners into a single SDK. Its encryption protocol was believed to protect user privacy by obfuscating device data. However, the researcher’s analysis shows that the encryption, based on a predictable keystream generator and lacking authentication, can be decrypted, revealing sensitive device information. Prior to this, the industry widely relied on ATT and IDFA restrictions to limit user tracking, but this breach indicates alternative fingerprinting methods are still effective.

“The cipher used by AppLovin is vulnerable because it employs a keystream generator that does not pass cryptographic standards, allowing me to decrypt thousands of requests.”

— Researcher

“This discovery shows that even with ATT restrictions, detailed device data can be used to track users across apps, raising serious privacy concerns.”

— Privacy advocate

Amazon

device fingerprinting privacy tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

It remains unclear whether AppLovin is aware of this vulnerability or has taken steps to fix or patch the encryption protocol. The full scope of how widespread the tracking implications are across all AppLovin-powered apps is also still being assessed. Additionally, the potential for malicious tampering or further exploitation of the cipher has not been fully explored.

Amazon

mobile device encryption analyzer

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

Further investigation is expected to determine whether AppLovin will update or replace its encryption protocol. Industry stakeholders may reassess privacy safeguards and consider alternative fingerprinting methods. Regulatory scrutiny could also increase if user privacy is compromised on a large scale.

Amazon

iOS privacy protection accessories

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Can this decrypted data be used to identify users across different apps?

Yes, the detailed device information can be used to deterministically re-identify users across multiple apps, even when ATT is denied.

Does this mean user privacy is compromised?

Potentially, yes. The decrypted data reveals that device fingerprinting can bypass some privacy restrictions, raising privacy concerns.

Has AppLovin responded to this discovery?

As of now, there is no public statement from AppLovin regarding this decryption or its implications.

Could this vulnerability be exploited maliciously?

Since the cipher lacks authentication, it could be tampered with, possibly enabling malicious actors to manipulate or extract data further.

Will this lead to regulatory action?

It is uncertain, but increased scrutiny from privacy regulators is possible if the tracking implications are confirmed to affect many users.

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Noise infusion banned from statistical products published by Census Bureau

The U.S. Department of Commerce has ordered the Census Bureau to cease using noise addition techniques in its statistical data, impacting data utility and privacy.

Over 181,000 AI Meeting Recordings Left Wide Open In Note Taking App

More than 181,000 AI-generated meeting recordings were found publicly accessible in a note-taking app, raising privacy and security concerns.

The Cheap Qwen Is A Weapon In The Open-Weight Price War

Alibaba’s release of Qwen3.8-Flash-Next, a cheap, capable open-weight model, aims to dominate developer adoption amid China’s open-weight AI surge and a global price war.

AmenGate: The Moment Before the Scroll

AmenGate, a Christian iPhone prayer-lock app, is planned for Lent 2027 with Screen Time gates, reviewed prayer packs and local-first data claims.