Mobile App Permissions
Name the feature each permission powers, or revoke it.
What Is Mobile App Permissions?
The dangerous app is rarely the sideloaded one. It is the free QR scanner from the official store, well reviewed and widely installed, asking for your contacts and calendar the moment it opens. Store review screens for malware but lets much excessive scope through. You answer an app's runtime permission prompts one at a time, then follow an exfiltration alert to two utility apps on a work phone, audit their permissions, uninstall one, revoke the other's extras, and apply one test: name the feature each permission powers.
What You'll Learn in Mobile App Permissions
- Recognize that Play Store and App Store review catches malware and policy violations but does not catch every permission that exceeds an app's stated purpose
- Answer Android runtime permission prompts one at a time, allowing what an app's purpose needs and tapping Don't allow on the rest
- Apply the one-sentence rule when reviewing permission requests: if you cannot name the user-facing feature a permission powers, the answer is no
- Identify Microphone, Contacts, and Calendar as high-leverage permissions that warrant the heaviest scrutiny on any non-essential app
- Audit installed app permissions in device Settings and choose between surgical revocation and full uninstall depending on whether the app has actively abused its permissions
- Adopt a quarterly permission audit routine for work phones, treating mobile devices with the same hygiene applied to laptops and workstations
Mobile App Permissions — Training Steps
-
A QR Scanner for Member Calls
Wednesday morning. Alice is on a call with a member who is reading off a stack of paper claim receipts. The native camera app can photograph each receipt, but the company-issued claim app needs the QR code from the back of each one - and the camera cannot extract it. She needs a free QR scanner, and she needs one in the next thirty seconds.
-
Searching for a QR Scanner
The Play Store loads. Featured apps fill the home screen, and a big search bar sits at the top.
-
Picking the Top Result
Four results come back. ScanZap Pro is at the top - 4.8 stars, over a million downloads, free, no nags. Alice would have to scroll past it to even see the alternatives.
-
Tapping Install
The app detail page loads. Stars, downloads, screenshots, and a green Install button at the top. The publisher is RegionWave Software - not a name Alice recognizes, but with 1M+ downloads and 4.8 stars she does not look twice at the byline. She taps Install. Notice what does not happen: no list of permissions to accept. Since Android 6, a Play Store install asks for nothing up front.
-
First Launch: The Camera Prompt
Alice opens ScanZap Pro. ScanZap Pro's launch screen appears, and before it shows a viewfinder, Android puts a dialog on top of it: Allow ScanZap Pro to take pictures and record video? This is a runtime permission prompt. Android shows one for each sensitive permission group, one at a time, when the app first asks for it. Reading a QR code is the whole point of a QR scanner, so this one makes sense.
-
Contacts? For a QR Scanner?
The viewfinder still has not appeared. A second dialog takes the first one's place: Allow ScanZap Pro to access your contacts? No QR code needs Alice's address book, and on her work phone that address book holds members, brokers and colleagues. The prompt is asking for something the app's purpose cannot explain.
-
And the Calendar
One more dialog: Allow ScanZap Pro to access your calendar? Nothing on the listing says why a QR scanner would need it. Even an app that adds events from QR codes can hand a new event to the Calendar app without reading Alice's calendar at all. Reading it would give the publisher every meeting title, attendee and dial-in code for her claim reviews.
-
The Scanner Works Anyway
Two refusals, and nothing breaks. ScanZap Pro reads the QR code on the first receipt, and Alice clears the member's stack before the call ends. Allowing Camera and refusing Contacts and Calendar cost her nothing. Two weeks later, during a power cut at home, she installs a free flashlight called Bright Torch . It asks for Camera, Location, Contacts and access to her files, one dialog after another, and she taps Allow on every one to get the light on.
-
A Quiet Monday Morning
It's 7:18 AM and Alice is in her home office with her first coffee. ScanZap Pro is still on her phone, still reading receipts every time a member calls in, with the one permission she gave it. Bright Torch is still there too, holding everything she tapped through during the power cut. Both are in good standing on the Play Store. Or so it has seemed.
-
An Email From the SOC
A new email from the Riverstone Security Operations Center sits at the top of her inbox - tagged urgent and titled in a way that ruins her morning before she has finished her coffee. The SOC has reconstructed exactly what each app on her phone has been accessing.
Security Framework Coverage
MITRE ATT&CK
- T1626 Abuse Elevation Control Mechanism (Mobile)
CIS Controls
- CIS 4 Secure Configuration of Enterprise Assets and Software
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.PS Platform Security