LiMP VPN
← All news

MAX Messenger Can Toggle Surveillance Per User

MAX Messenger Can Toggle Surveillance Per User

In short: On September 24, 2026, research lab InterSecLab, working with the RKS Global project, published a nine-week technical teardown of MAX, Russia's leading messaging app. The finding: a number of data-collection and tracking features can be switched on or off server-side for individual accounts, without any app update reaching the user's device. Documented capabilities include reading a device's public IP, VPN status, mobile carrier, and network environment. VK, the app's developer, called the report's conclusions false.

What the researchers found

InterSecLab analyzed the Android build of MAX 26.12.0 (build 6664) by intercepting app data before cryptographic processing and cross-referencing it against client code. The central finding is architectural: the developer can remotely change which features are active for a specific account without shipping an update — toggling things like network diagnostics, VPN detection, and voice transcription per account.

According to the report, the app can collect a user's public IP address, on-device VPN status, mobile carrier information, unhashed contact data, and network environment details. Researchers also concluded that MAX does not use end-to-end encryption (E2EE) for regular chats — meaning the server infrastructure is technically positioned to process message content after the transport channel is decrypted.

Why a messenger needs to know if a VPN is running

A separate finding is that MAX can detect a VPN running directly on the device and block sending messages until it's disabled, while a VPN configured at the router level isn't detected this way. The ability to distinguish a VPN tunnel isn't unusual for mobile software on its own, but combined with per-account server-side control over feature sets, it raises the question of on what basis — and against whom specifically — such checks get activated.

It's the combination of these findings — granular, account-level control over data-collection features, the absence of E2EE, and network diagnostics that include VPN status — that drove coverage in outlets including Meduza, SecurityLab, and Radio Svoboda writing about digital privacy in Russia.

What this means for an ordinary user

MAX is, per Mediascope data, the leader of the Russian messenger market by average daily audience in 2026 — effectively a mass-market service. For a typical user, the report's findings mean that the amount of data collected about them isn't necessarily uniform across accounts; it can vary at the service operator's discretion, invisibly to the user. The lack of E2EE in chats further means message confidentiality rests on company policy and internal procedures rather than on a mathematical guarantee that no third party can access the content.

VK, for its part, rejected the report's conclusions, calling the material inaccurate, and specifically denied the mention of "secret chats," which the company says never existed in MAX.

How to reduce your exposure when using messengers with weak privacy guarantees

  • Separate sensitive conversations from everyday ones — for genuinely private discussions, use a messenger with proven end-to-end encryption by default rather than relying on any single service's claims.
  • Review app permissions — restrict access to contacts, location, and microphone to the minimum your phone's settings allow.
  • Encrypt the connection independently of the app itself. LiMP VPN can't change how a messenger processes messages internally, but it encrypts your traffic before it leaves your device and hides your real IP address from intermediate network nodes — a separate layer of protection useful with any app, including on public Wi-Fi. For more on the technical side, see our piece on what an ISP can actually see about the sites you visit.
  • Follow independent research — reports from organizations like InterSecLab and specialized outlets help surface changes in app behavior before they become a widespread problem. If you suspect you're being targeted specifically (rather than caught up in general service telemetry), it's also worth reading about signs of spyware on a phone.

Sources