TAIPEI (Taiwan News) — The National Security Bureau on Wednesday warned that Chinese social media mobile apps such as TikTok, WeChat, RedNote, and Weibo pose significant cybersecurity risks, including the potential collection and cataloging of facial biometrics.
The NSB said it tested five Chinese apps popular in Taiwan and found all exhibited "excessive data collection" and "privacy infringement," per CNA. Chinese social networking and e-commerce platform RedNote was found to be the worst offender.
The NSB said international concerns have grown in recent years over Chinese-made apps, with governments and research institutions globally warning that these platforms could expose users to cybersecurity threats. The bureau urged the public to remain vigilant and avoid downloading questionable Chinese apps.
To prevent China from illicitly gathering personal data from Taiwanese users, the NSB said it conducted a joint investigation with the Ministry of Justice Investigation Bureau and the Criminal Investigation Bureau. The effort was based on findings from international cybersecurity reports and carried out under the National Intelligence Work Act.
The five apps tested, RedNote, Weibo, TikTok, WeChat, and Baidu Cloud, were assessed using 15 criteria under version 4.0 of the Ministry of Digital Affairs’ Basic Information Security Testing Standard for Mobile Applications. The indicators were divided into five categories of violation: personal data collection, excessive permission usage, data transmission and sharing, system information extraction, and biometric data access.
The results showed all five apps violated multiple indicators. Rednote failed to meet all 15 criteria, while Weibo and TikTok each failed 13, WeChat 10, and Baidu Cloud 9. The NSB said these findings indicate that “China-made apps present cybersecurity risks far beyond the reasonable expectations for data-collection requirements taken by ordinary apps.”
All five apps were found to excessively gather personal data and misuse permissions, including access to facial recognition data, screenshots, clipboard contents, contact lists, and location information. They also collected sensitive system information, such as app lists and device parameters.
The NSB warned that “users’ facial features may be deliberately harvested and stored by those apps.”
The bureau also found that all five apps transmitted data packets back to Chinese servers, raising the risk of third-party misuse. Under China’s Cybersecurity Law and National Intelligence Law, Chinese companies are obligated to hand over user data to state security and intelligence agencies, posing further privacy risks to Taiwanese users.
Governments in the US, Canada, the UK, and India have issued bans or warnings against certain Chinese apps, while the European Union has launched investigations and imposed heavy fines under its General Data Protection Regulation. Taiwan has already prohibited the use of Chinese ICT products' hardware and software in government agencies.
The NSB concluded by emphasizing the widespread cybersecurity risks found in the tested apps and advised the public to enhance their cybersecurity awareness and avoid downloading suspicious Chinese apps to protect personal privacy and trade secrets.





