← Antivirus
D

Avast / AVG

Serious concerns
Gen Digital · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.avast.android.mobilesecurity
Manufacturer: Gen Digital

The bottom line

Avast was installed on 435 million devices as antivirus protection. Through its subsidiary Jumpshot, it sold those users' complete browsing histories — every URL, every search, timestamped to the second — to Google, Pepsi, Sephora, Home Depot, and over 100 other companies. The FTC fined Avast $16.5 million in 2024. The antivirus you installed to protect yourself was the biggest spyware on your computer. Avast told users the data it sold through Jumpshot was "anonymous" and "de-identified." The FTC proved that was false — each user was assigned a unique persistent identifier that linked every website visit back to their individual device. Researchers at PCMag and Vice's Motherboard obtained leaked Jumpshot data and were able to identify specific users from their browsing patterns. "Anonymous" meant "we gave you a number instead of your name.".

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Audited by: Unknown (ISO 27001, Jan 2022)
An audit is a snapshot, not a guarantee. How reliable are these auditors?
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
1/4 LOW
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
Use ClamAV or Malwarebytes instead
Zero telemetry (ClamAV) or no data selling scandals (Malwarebytes)
See report →
7Contradictions
0Critical
7High
0Medium
8Sources
Findings by concern
Spying 3/4 HIGH 3 findings
⚡ highpolicy claims vs regulatory findings
Avast told users the data it sold through Jumpshot was "anonymous" and "de-identified." The FTC proved that was false — each user was assigned a unique persistent identifier that linked every website visit back to their individual device. Researchers at PCMag and Vice's Motherboard obtained leaked Jumpshot data and were able to identify specific users from their browsing patterns. "Anonymous" meant "we gave you a number instead of your name."

What they claim: 'Avast does not sell user data' and data is 'anonymized.'

What we found: FTC charged Avast with deceiving users. Unique browser identifiers allowed re-identification. Data sold in non-aggregate form. Avast settled for $16.5M and accepted 20-year monitoring.

⚡ highfirmware analysis vs policy claims
Antivirus software has root access to your entire computer — it can see every file, every process, every network connection. Avast used that total access to build Jumpshot, a data harvesting business worth $66 million annually that recorded everything 435 million users did online. The tool that sees everything on your computer was using that access to watch everything you do on the internet and sell it.

What they claim: Avast's kernel-level access is used solely for security protection.

What we found: Antivirus has deepest system access: kernel scanning, real-time monitoring, web filtering, HTTPS inspection. Avast used this to harvest browsing data for commercial sale. The security tool became the surveillance tool.

⚡ highpolicy claim vs third party research
Avast was fined $16.5 million for selling your browsing data. Their HTTPS scanning feature — still enabled by default in 2026 — installs a certificate that lets them decrypt every encrypted connection you make. The US government warned this practice weakens security. Researchers found it introduces broken encryption. The company proven to monetise your browsing history still has a default-on tool that can read everything, including your banking and medical visits.

What they claim: Avast HTTPS scanning protects users from encrypted threats while maintaining security.

What we found: Avast's HTTPS scanning is enabled by default (confirmed February 2026) and installs a root CA certificate to intercept all encrypted traffic. CISA Alert TA17-075A warned this practice "drastically reduces connection security." The NDSS 2017 study by Google, Mozilla, Cloudflare and three universities found antivirus HTTPS interception introduced support for known-broken ciphers in 10-40% of connections. Avast — already fined $16.5M for selling 8 petabytes of browsing data — now has default access to decrypt every HTTPS connection on users' machines. The company caught selling browsing data still has, by default, the ability to read all encrypted traffic.

Honesty 4/4 EXTREME 4 findings
⚡ highpolicy claims vs firmware analysis
Avast was installed on 435 million devices as antivirus protection. Through its subsidiary Jumpshot, it sold those users' complete browsing histories — every URL, every search, timestamped to the second — to Google, Pepsi, Sephora, Home Depot, and over 100 other companies. The FTC fined Avast $16.5 million in 2024. The antivirus you installed to protect yourself was the biggest spyware on your computer.

What they claim: Avast protects user privacy by blocking third-party tracking.

What we found: FTC: Avast sold 8 petabytes of browsing data from 435M+ users through Jumpshot to 100+ companies (Google, Microsoft, Pepsi). Every click, search, purchase with unique identifiers. $16.5M fine, 20-year compliance order.

⚡ highapp permissions vs policy claims
Avast's browser extensions (Avast Online Security and AVG Web TuneUp) recorded every website users visited and transmitted it to Avast's servers. Security researcher Wladimir Palant reported the behaviour. Mozilla removed the extensions from Firefox. Google removed them from Chrome. Opera removed them. The extensions that promised to "protect your browsing" were logging it instead — and it took browser vendors, not Avast, to stop it.

What they claim: Browser extensions provide additional security.

What we found: Researcher Wladimir Palant: extensions collected complete browsing history with unique user IDs. Mozilla and Google removed from stores. Extensions sent far more data than needed.

⚡ highpolicy claims vs regulatory findings
AVG and Avast are the same product with different names — same codebase, same data collection, same parent company (Gen Digital, which also owns Norton). When Avast was caught selling browsing data through Jumpshot, AVG was doing the same thing. Gen Digital now controls Norton, Avast, AVG, and LifeLock — four brands that appear to compete but share the same data practices and the same $16.5 million FTC fine.

What they claim: AVG is a separate, independent product.

What we found: Avast acquired AVG ($1.3B, 2016). Same engine, same Jumpshot pipeline. Now both under Gen Digital (Norton parent, $8.1B acquisition 2022). Six brands, one company.

⚡ highfirmware analysis vs regulatory findings
Avast shut down Jumpshot in January 2020, days after a Motherboard/PCMag investigation. The FTC investigation took four more years. The $16.5 million fine was announced in 2024. For the 435 million users whose browsing histories were sold from 2014 to 2020, justice arrived six years late and paid roughly 3.8 cents per person. Avast's revenue during those six years of selling data: hundreds of millions.

What they claim: Jumpshot was shut down and data practices reformed.

What we found: Closed Jan 2020 only after media exposure. FTC ordered deletion of data AND algorithms. 20-year monitoring. Gen Digital owns the same infrastructure. Consumer payments began Dec 2025 -- 6 years later.

Sources