Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 952

Potentially Unwanted Program (PUP)

Reviewed byCybersecurity entrepreneur & security researcher

What is Potentially Unwanted Program (PUP)?

Potentially Unwanted Program (PUP)Software that is not strictly malicious but installs without clear consent, behaves intrusively, or degrades user experience — for example, bundled toolbars, adware, or aggressive optimizers.


Potentially Unwanted Programs (PUPs), also called Potentially Unwanted Applications (PUAs), are programs that a user might not want even if they nominally agreed during installation. They are commonly delivered through software bundlers that hide opt-out checkboxes, freeware download portals, or trojanized installers. Typical PUP behaviour includes injecting ads, changing browser settings, adding background services, collecting telemetry, or pushing paid "upgrades." Endpoint products classify them under a separate "PUP" or "PUA" category, often with a default block. Defences include downloading software from official sources, reading installation screens carefully, using package managers, and enabling PUA detection in security tooling.

Examples

  1. 01

    Free PDF readers that bundle browser toolbars and change the default search engine.

  2. 02

    "System optimizers" that scare users into buying a paid license.

Frequently asked questions

What is Potentially Unwanted Program (PUP)?

Software that is not strictly malicious but installs without clear consent, behaves intrusively, or degrades user experience — for example, bundled toolbars, adware, or aggressive optimizers. It belongs to the Malware category of cybersecurity.

What does Potentially Unwanted Program (PUP) mean?

Software that is not strictly malicious but installs without clear consent, behaves intrusively, or degrades user experience — for example, bundled toolbars, adware, or aggressive optimizers.

How do you defend against Potentially Unwanted Program (PUP)?

Defences for Potentially Unwanted Program (PUP) typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for Potentially Unwanted Program (PUP)?

Common alternative names include: PUP, Potentially Unwanted Application (PUA).

Related terms