Our first network security analysis of the popular social media app, #RedNote, has revealed some major red flags 🚩🚩🚩. The app is used by over 300 million users worldwide - but its network encryption falls short. Read the report: https://citizenlab.ca/2025/02/network-security-issues-in-rednote/
Network Security Issues in RedNote - The Citizen Lab

Our first network security analysis of the popular Chinese social media platform, RedNote, revealed numerous issues with the Android and iOS versions of the app. Most notably, we found that both the Android and iOS versions of RedNote fetch viewed images and videos without any encryption, which enables network eavesdroppers to learn exactly what content users are browsing. We also found a vulnerability in the Android version that enables network attackers to learn the contents of files on users’ devices. We disclosed the vulnerability issues to RedNote, and its vendors NEXTDATA, and MobTech, but did not receive a response from any party. This report underscores the importance of using well-supported encryption implementations, such as transport layer security (TLS). We recommend that users who are highly concerned about network surveillance from any party refrain from using RedNote until these security issues are resolved.

The Citizen Lab
Both the #iOS and #Android versions of RedNote fetch viewed images and videos without encryption, leaving millions of users’ data vulnerable to network eavesdroppers.
We also found that RedNote transmits device metadata, such as location, description, and serial number with insufficient encryption. This can potentially expose sensitive information to network attackers.
These vulnerabilities leave user data exposed to potential eavesdropping, device attacks, and network surveillance. High-risk users should avoid using the app until these vulnerabilities are addressed.
We disclosed these security issues to RedNote, and the related software development kit vendors NEXTDATA, and MobTech, but as of yet, have not received a response from any party.