Home » Latest News » EU age verification app faces early security scrutiny as researchers find ways to bypass protections

EU age verification app faces early security scrutiny as researchers find ways to bypass protections

EU age verification app faces early security scrutiny as researchers find ways to bypass protections

The European Commission’s new age-checking app has drawn swift criticism from cybersecurity and privacy experts, who say weaknesses in the publicly released code could allow users to bypass safeguards.

The concerns surfaced just days after EU officials presented the tool as a key step to protect minors online.

Commission President Ursula von der Leyen introduced the app in Brussels as a technically ready solution that would help websites confirm whether a person is above a required age. Because the project is open source, researchers immediately examined the code and began publishing findings about potential flaws.

Researchers flag privacy and bypass risks

Security consultant Paul Moore said the app could store sensitive information on a device in ways that are not adequately protected, and claimed he was able to break protections within minutes.

French ethical hacker Baptiste Robert separately reported that some authentication controls could be bypassed, potentially weakening PIN or biometric checks.

Cryptography researcher Olivier Blazy warned that if access controls can be sidestepped, a verified adult device could be reused by a minor to prove an age threshold. Several experts argued that a rushed rollout could damage trust in future EU digital identity tools.

Commission says code is a demo

The Commission has defended the initiative while acknowledging the code is still evolving, describing the release as a demo intended for testing and development.

Officials have said reported issues are being addressed, while insisting the concept is viable and improvements will continue.

The debate is unfolding as EU institutions and member states explore stricter age assurance for social media and adult content, amid growing political pressure to act. Critics, including large groups of security and privacy specialists, argue that age assurance can create new data risks and may be circumvented with tools such as VPNs.

The app is tied to broader work on European digital identity, including wallet-style solutions designed to share only the minimum data needed for a check.

Supporters say privacy-preserving methods can reduce data exposure, but experts stress that real-world implementation and independent security assessments will determine whether citizens can trust it.