FINDING · DEPLOYMENT

The Chivo Wallet app — the official El Salvador government Bitcoin wallet with 1M+ downloads — uses Microsoft CodePush to check 'codepush.appcenter.ms' for JavaScript/HTML/CSS updates each time it opens, bypassing Google Play Store review entirely. This allows the government of El Salvador to push arbitrary behavioral changes to all users' devices without any app store vetting or user notification.

From 2024-kujath-analyzingAnalyzing Prominent Mobile Apps in Latin America · §7.3, Table 4 · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
generic

Extracted by claude-sonnet-4-6 — review before relying.