A concerning security finding reveals that certain low-cost Android smartphones are arriving in consumers' hands with malware pre-installed directly into the system software. Because the malicious code is baked into the devices before they are unboxed, users are exposed to potential security and privacy threats from the moment they power on their phones.

Pre-installed malware is particularly dangerous because it often resides in system partitions, making detection and removal exceptionally difficult with standard security apps. In many cases, these hidden threats can harvest sensitive personal data, download unauthorized applications, or display intrusive advertisements without the owner's knowledge or consent.

The problem underscores persistent supply-chain vulnerabilities within the budget device ecosystem, where third-party software vendors or intermediaries may compromise firmware integrity prior to retail distribution. Consumers looking for affordable alternatives often face the highest risks when device provenance is unclear.

For full details and in-depth analysis of the findings, check the original coverage on Android Authority.