The Fitbit Gallery is a one-stop shop for approved Fitbit apps, like Spotify or Starbucks Card. And while Fitbit manually scans all published Gallery apps for malware, shareable “private” apps don’t get the same treatment. If someone emails you a download link for a Fitbit app, ignore it!

Fitbit lets developers upload “private” apps to the Gallery to aide in testing. Unfortunately, anyone with a download link can install a private app. Bad actors can share a private download link to spread data-collecting malware, a threat identified by Kevin Breen and publicized by BleepingComputer.


Kevin Breen, threat research director at Immersive Labs, successfully uploaded a malicious private app to the Gallery and used it to steal GPS location, heart rate, height, and age data from test devices. On Android, the malicious app could also read any calendars connected to the Fitbit. Breen could even configure the app to scan and access network tools like routers and firewalls, thanks to the Fitbit fetch API.

Thankfully, Kevin Breen submitted his research to the Fitbit company, which responded by adding warnings to private app downloads. Fitbit also plans to opt-out private app permissions by default, giving users the choice to manually provide access to their age, contacts, and other information. As always, Fitbit scans Gallery apps for malicious code before they’re published to the public Gallery page.

Source: Kevin Breen via BleepingComputer

Visit GHsitemap for all information on smartphone prices and beyond. Get all the needed information on smartphone features and other relevant tech stories. Follow us all social media platforms. Thanks
McKourage, Chief editor at GHsiteMap


We strive hard to prevent all forms of errors in our articles, however, should you detect any error or misinformation on SmileTimes, Contact us.

Subscribe to our RSS Feed here, so you read our latest  publications

What do you think?

You May Also Like

A Quick Guide to Babyface’s Net Worth

Babyface.s is a famous R&B singer and songwriter with an estimated net…

Matt Dickerson – Arizona Cardinals Defensive End

The high school career of Dickerson has been highlighted by his stellar…

Kid Harpoon Wife

Thomas Edward Percy Hull professionally known as Kid Harpoon is an English…

Razer Blade Stealth 13 gets a new HD display, better processors -GHsitemap

Get ready for a new version of the Razer Blade Stealth 13,…