Temu and your data: permissions, Pinduoduo malware and privacy
Is Temu dangerous? 29 permissions, Pinduoduo malware exploiting an Android zero-day, the Swiss NTC report, dark patterns: a complete security analysis.

Temu and your data: permissions, Pinduoduo malware and privacy, the dark side of the app
Is Temu dangerous for your data? The question keeps coming back since the meteoric arrival in Europe of the “little orange app” with unbeatable prices. Officially, Temu is just a marketplace. Unofficially, its parent company has already been caught red-handed exploiting an Android zero-day in a sister app, its early versions requested 29 permissions, and an independent Swiss report flagged two technical anomalies typical of malware.
You have had that strange feeling before: you talk about a product with a friend, and a few minutes later an ad for that very product shows up on your phone. Coincidence or spying? The reality is both simpler and more worrying, and Temu is the perfect illustration. This article explains how advertising profiling works, retraces the history of Temu and Pinduoduo, details our own analysis of the app’s permissions, summarises the conclusions of the NTC report and answers the question: should you use Temu?
- Temu: launched in September 2022 in the United States, in France in April 2023, 18 million unique monthly visitors in France in 2024 and 12 million parcels a month.
- Pinduoduo, the sister app, was pulled from the Google Play Store in March 2023 after malware exploiting the zero-day CVE-2023-20963 was discovered.
- 29 permissions requested by early Temu versions, including precise location, camera, storage, call information and system alerts.
- NTC report (December 2024): dynamic code loading and a proprietary encryption layer on top of HTTPS.
- Dark patterns, unfair competition and an offer of 100 euros for lifetime access to your data.
- Current version: 12 permissions, but still access to exact location.
Is my phone listening to me? How advertising profiling works
Yes and no. In fact, your phone does not need to listen to you: the massive collection of your data is enough. Tech giants like Google or Meta build ultra-precise advertising profiles: age, gender, place of residence, interests, websites visited and even the people you are in contact with. This is targeted advertising, which can be broken down into four levels:
- The data you hand over voluntarily, the base of the pyramid: name, age, email address, city, everything you fill in at sign-up.
- Your activity on their services: every Google search, every YouTube video, every Instagram “like”, every product clicked on Amazon. Everything is recorded, analysed and categorised.
- Off-platform tracking, the most invisible one. Thanks to hidden pixels and cookies embedded on millions of partner websites, Meta and Google follow you even outside their services. A gardening article, a tiramisu recipe, a pair of shoes abandoned in a basket: everything joins your profile, and those shoes will follow you around for days.
- Data brokers: a huge hidden market that aggregates loyalty programmes, electoral rolls, public registers and data from other apps, to add information to your profile that you never provided, such as your socio-professional category or the composition of your household.
That is where apps like Temu come in, with an even more aggressive approach.
The story of Temu and Pinduoduo
Officially launched in September 2022 in the United States, Temu quickly became the most downloaded app. It arrived in France in April 2023 and met with dazzling success: 18 million unique monthly visitors in 2024, 12 million monthly parcels representing nearly 20% of La Poste’s traffic, and global revenue in the region of 50 billion euros.
Temu belongs to PDD Holdings, a Chinese parent company that also owns Pinduoduo, an e-commerce giant in China founded in 2015 with more than 750 million users in 2023. This is where the story gets complicated: in March 2023, the Pinduoduo app was removed from the Google Play Store after malware was discovered inside.
A zero-day exploited by a shopping app
The analysis is particularly worrying: the app abused CVE-2023-20963, an Android zero-day.
Thanks to this flaw, the app could escalate privileges, grant itself rights far beyond those of a standard app without user interaction, and take near-total control of the device. Analyses by Lookout, Kaspersky and independent researchers highlighted the following capabilities:
- backdoor installation, for remote and secret access to the device;
- data theft from other apps, including notifications and private messages, as well as the user’s files;
- activity monitoring across other apps;
- installation of additional malware in the background;
- persistence and concealment: difficult if not impossible to uninstall, able to impersonate other apps and hide its battery consumption.
That is not the most alarming part. A CNN report, quoting an anonymous employee, revealed that a team of about 100 engineers and product managers had been set up in 2020 to actively search for vulnerabilities in Android phones, exploit them and collect behavioural data to increase profits. Source code analyses confirmed the presence of exploit code targeting the systems of various manufacturers.
Our analysis: 29 permissions in early Temu versions
To illustrate the point, we obtained one of the first versions of Temu and ran a static analysis with MobSF. The result is alarming: the app requests 29 permissions, including:
- access to precise and approximate location;
- posting notifications;
- camera access;
- reading and writing external storage;
- retrieving technical information about the phone, including the phone number and call information;
- displaying system alerts that overlay other apps;
- automatic launch at device startup.
Far beyond what a shopping app needs.
The NTC report: two technical red flags
In December 2024, the NTC, an independent Swiss non-profit specialised in cybersecurity research, published a fifty-page investigation into Temu’s security. Two major anomalies stand out.
Researchers, and even a US attorney general, have called Temu “spyware” and “dangerous malware”, able to bypass privacy settings and access almost all the data on the phone. Temu denies these allegations, but the links with Pinduoduo and the observed techniques raise serious questions. One offer, since withdrawn, even proposed 100 euros in exchange for lifetime access to your personal data.
Old version versus new version
Out of curiosity, we compared the current app (end of July 2025) with the old version. Result: 12 permissions against 29. All the controversial permissions are gone, except access to exact location. Rather good news. Or rather good camouflage.
Business model, unfair competition and dark patterns
Temu’s model relies on extremely low prices, defying all competition, with a direct impact on local retail and other e-commerce players. Some experts estimate that Temu loses money on every order to flood the market and push out the competition. This policy raises questions about product quality and working conditions in factories, and Temu is accused of unfair competition by exploiting loopholes in customs regulations.
To push you to buy ever more, the app uses dark patterns, rigged interfaces designed to deceive:
- fake countdowns to create a sense of urgency;
- incessant notifications;
- pricier versions of a product that suddenly appear;
- an obstacle course to delete your account.
Several European consumer associations have filed complaints against Temu for these manipulative practices.
How to protect yourself if you use Temu
- Use the website rather than the app: a browser drastically limits the accessible permissions.
- Refuse non-essential permissions, especially precise location.
- Use a dedicated email address and a virtual bank card.
- Never link your social accounts to the app.
- Regularly check the permissions granted in your Android or iOS settings.
Frequently asked questions about Temu’s security
Is Temu spyware?
No public evidence establishes that the current Temu app contains malware. However, its parent company was caught red-handed with Pinduoduo, and the NTC report flags techniques (dynamic code loading, proprietary encryption) usually associated with malware. Caution is warranted.
What data does Temu collect?
At a minimum, account, browsing and purchase data, as well as whatever the granted permissions allow: location, device information and, in older versions, much more. The proprietary encryption layer prevents precise verification of what is transmitted.
Are Pinduoduo and Temu the same app?
No, but they belong to the same group, PDD Holdings. Pinduoduo targets the Chinese market and was removed from the Play Store in March 2023; Temu targets international markets.
Can Temu be used safely?
The risk can be reduced by using the website rather than the app, limiting permissions and compartmentalising payment methods, but it does not disappear: your account and purchase data are still processed by a company whose practices have been called into question.
Key takeaways
Temu, a simple bargain platform or a digital Trojan horse? The attractive prices hide a much darker reality: a destructive business model, psychological manipulation practices and, above all, major risks for your privacy and the security of your data.
The question is no longer just “is my phone listening to me?”, but “to whom am I handing the keys to my digital intimacy for a few euros of savings?”. The choice is yours. But now, you know. To go further on devices and apps that listen to us, also read our analysis of the Friend pendant.
Sources
- CSIS, Looking Beyond TikTok: The Risks of Temu
- NTC (Switzerland), Temu security analysis (December 2024)
- NTC (Switzerland), press release
- Protergo, CISA warns of Android bug exploited by Chinese app to spy on users
- Thales, Pinduoduo malware analysis
- Natto Thoughts, Pinduoduo: when business success comes with a price
- Grizzly Research, We believe PDD is a dying fraudulent company and its shopping app Temu is cleverly hidden spyware
- Nexa, The cybersecurity risks of the Chinese group Pinduoduo (Temu)
- LeBigData, Pinduoduo and cybersecurity
- Negg, Temu app security under fire
- Malwarebytes, Temu sued for being “dangerous malware” by Arkansas Attorney General
- vzbv, Amazon, TikTok, Temu: manipulative designs remain a problem
- Les Echos, E-commerce: Temu targeted by a complaint for consumer manipulation
- Carnets du Business, Online manipulation: Temu under fire from European critics
- Capital, Temu ends its controversial offer in exchange for lifetime personal data
- Le Parisien, Buying personal data for 100 euros: Temu removes its offer
- FashionUnited, Everything you need to know about Temu
- SendPulse, Targeted advertising