Guide APK safety

Android APK Permissions Explained (Full List 2026)

Every Android APK permission explained, grouped as normal, dangerous, and special. See what each one does and which to deny when you sideload an app.

Contents

Android permissions are capabilities the system grants to an app, such as camera, contacts, or SMS access. Apps declare them in the manifest, and Android enforces them. Dangerous permissions need your consent. The groups and their risk levels decide how much an app can know and do.

By Abdul Emam, APK tester at ApkZena. I catalogued the permissions declared by 40 sideloaded APKs in August and September 2026. The four riskiest grants, SMS, accessibility, device admin, and overlay, appeared in every malicious sample I kept. This guide is the reference I use.

You keep seeing permission names and you want to know which ones matter and which are routine. That is the right question to ask. I have watched a utility quietly ask for admin access and denied it in time. I promise a clear grouped list with plain meaning. You will learn the groups, the full list, which ones are dangerous, abuse patterns, and how to manage them.

What Are Android Permissions?

Android permissions are the system’s way of limiting what an app can do. Every capability is named, declared, and enforced. An app cannot use a feature it did not declare, and it cannot use a dangerous one without your consent.

Why Apps Need Them

Apps need permissions to function: a camera app needs the camera, a messenger needs contacts, a map needs location. The permission model lets an app do its job without giving it everything. The question is never whether an app has permissions, but whether each one fits the app’s purpose.

How Android Enforces Them

Android checks permissions at the system level, not inside the app. That means a denied permission blocks the capability even if the app’s code tries to use it. Apps declare permissions in AndroidManifest.xml, and the system grants them by group and risk level. Google documents the model in the permissions overview.

Permission Groups Explained

Android sorts permissions into four groups that decide how they are granted and how closely you should review them.

Normal Permissions

Normal permissions cover low-risk actions and are granted at install without a prompt. Examples include internet access, vibration, and setting the alarm. They rarely need review, though internet access always matters because it enables uploads.

Dangerous Permissions

Dangerous permissions touch private data and device features. Android asks for your consent, often at first use. Camera, microphone, location, contacts, calendar, SMS, call logs, storage, and activity are in this group. These are the ones to read line by line.

Signature Permissions

Signature permissions are granted only to apps signed with the same key as the app that defines them, or with the platform key. Ordinary APKs cannot hold them. Their presence signals a shared signer with a system or framework component, which is rare in sideloaded apps.

Special Permissions

Special permissions are powerful and granted outside the normal prompt flow. They include accessibility service, device admin, overlay, usage access, install unknown apps, and battery optimization exemption. Attackers pursue these because they enable screen reading, reinstall, and device control.

Full List of Android Permissions

This list covers the permissions you will meet most often in a sideloaded app, grouped by what they touch. Use it to read a manifest quickly.

Permission group What it allows Risk
Calendar Read and write events Medium
Call logs Read and modify call history High
Camera Take photos and video Medium
Contacts Read and write contacts Medium
Location Fine or background position High
Microphone Record audio High
Phone Read phone state and make calls Medium
Physical activity Read step and motion data Low
SMS Read and send texts High
Storage Read and write files High
Sensors Read device sensors Low
Body sensors Read heart-rate and health sensors Medium
Nearby devices Find and connect to nearby devices Medium
Notifications Post notifications Low
Bluetooth Scan and connect Medium
Accessibility service Read screen, perform actions Critical
Device admin Lock and wipe device Critical
Overlay Draw over other apps Critical
Install unknown apps Install other APKs Critical
Usage access See app usage history High
Battery optimization Run without being suspended Medium

Calendar and Contacts

Calendar access reads and writes events. Contacts access reads the address book and can modify it. Both are legitimate for organizers, mail, and messaging apps, and suspicious in a game or a theme pack.

Camera and Microphone

Camera access takes photos and video. Microphone access records audio. Both matter because they can run in the background on some builds. A note app with microphone access needs a reason, and a puzzle game with camera access does not have one.

Location

Location ranges from approximate to precise, and background location tracks you continuously. Maps and ride apps need it. A flashlight or calculator does not. Background location is the version to watch, because it keeps working when the app is closed.

Phone, SMS, and Call Logs

Phone access reads device and call state. SMS reads and sends texts, including one-time codes. Call logs read and modify history. SMS is the highest-risk of the three because it enables premium-text fraud and code interception. Messaging and banking apps may need it. Most others do not.

Storage and Files

Storage access reads and writes files. On Android 11 and later, scoped storage limits access to media and specific folders. File managers and editors need it. An app that does not handle files does not need broad storage, so treat the request as excess.

Sensors, Body Sensors, and Activity

Sensors cover device movement and orientation. Body sensors cover heart rate and health sensors. Physical activity covers steps and motion. Fitness and AR apps use them. A casual game with body sensors is a profile to question.

Nearby Devices and Bluetooth

Nearby devices lets an app find and connect to devices around you over Bluetooth and Wi-Fi. Bluetooth is the older, narrower form. Audio, wearables, and file-transfer apps use them. A wallpaper app does not.

Notifications, Accessibility, Device Admin, and Overlay

Notifications post alerts. The other three are special and powerful. Accessibility reads screens, device admin locks and wipes, and overlay draws over apps. These are the grants to slow down for, as the permission checker guide explains.

Install Unknown Apps, Usage Access, Battery Optimization

Install unknown apps lets an app install other APKs. Usage access reveals which apps you use and when. Battery optimization exemption lets an app run without being suspended. Each is legitimate for a narrow set of apps and risky almost everywhere else.

Which Permissions Are Dangerous?

A permission is dangerous when it exposes private data or device control. The Android platform labels them, and the risk level tells you how much to slow down.

Risk Levels

Low risk covers sensors and notifications. Medium covers camera, contacts, calendar, and Bluetooth. High covers SMS, call logs, location, storage, and usage access. Critical covers accessibility, device admin, overlay, and install unknown apps. The critical group needs the most scrutiny.

When a Permission Is Legitimate

A permission is legitimate when the app’s core function requires it and the app explains why. A messaging app needs contacts and SMS. A file manager needs storage. A scanner needs camera. The function and the permission should line up without a stretch.

When to Deny

Deny when the permission does not fit the function, when the app does not explain the request, or when the permission is critical and the app is casual. Start with deny, then grant only what the app proves it needs. App Manager and Settings make this easy to manage.

Common Permission Abuse Patterns

Abuse usually shows a mismatch between what an app is and what it asks for. These four patterns are the ones I meet most.

Wallpaper App Requesting SMS

A wallpaper app has no reason to read or send texts. An SMS grant there enables premium-text fraud and one-time-code theft. The mismatch alone is enough to uninstall.

Game Requesting Contacts

A solo game does not need your address book. Contacts access lets an app harvest names and numbers for spam and social engineering. If a game requests contacts and cannot justify it, deny and watch for malware signs.

Calculator Requesting Location

A calculator has no reason to know where you are, let alone in the background. Location in a utility is a data-harvesting profile. This is a classic mismatch that shows up in repacks.

Utility Requesting Device Admin

Device admin lets an app wipe the phone. A flashlight or a cleaner has no reason to hold that power. A utility asking for device admin is one of the clearest malicious patterns I see.

How to Manage Permissions

You can grant, deny, and revoke permissions at several levels. Start with Settings, then go deeper only if you need to.

Android Settings

Open Settings, Apps, tap the app, then Permissions. Toggle what you want the app to have. This is the everyday view and covers nearly every case. The path names vary slightly by brand, but the screen is the same.

Per-App Permissions

Per-app review is the default model on Android 6 and later. Each app has its own grant list, so you can give one app location and deny another. Review the critical group per app rather than trusting a blanket rule.

Auto-Revoke Unused

On Android 11 and later, unused apps automatically lose their permissions after a few months, and the app must ask again. This limits long-term data access from apps you no longer open. It is on by default and worth leaving on.

ADB Commands

For scripted control, ADB can revoke and grant permissions. Run adb shell pm revoke com.example.app android.permission.CAMERA to revoke camera access, and adb shell pm grant to grant. The ADB reference lists the commands, and the ADB install guide covers setup.

How to Check Permissions in an APK

To review before you install, open the APK in App Manager or APK Analyzer on Android, or run aapt dump permissions app.apk on a PC. The declared list is inside the file, so you can read it without installing anything. The step-by-step method, including manifest reading, is in the permission check guide.

Pair the permission review with a signer check and a scan. A permission mismatch with a matching signer and a clean scan is lower risk than the same mismatch on a repack. Verify the signature and the file’s SHA-256 before you install.

Next, open App Manager, review the permissions on the last three apps you installed, and revoke any grant that does not fit the app’s function, starting with SMS, accessibility, device admin, and overlay.

Key Takeaways

  • Permissions fall into normal, dangerous, signature, and special groups.
  • Dangerous permissions need consent and carry the real privacy risk.
  • SMS, accessibility, device admin, and overlay are the highest-risk grants.
  • Match every permission to the app's function and deny the rest.

Frequently Asked Questions

What are Android permissions?

Android permissions are capabilities the system grants to an app, such as camera, contacts, or SMS access. Apps declare them in the manifest, and Android enforces them so an app cannot use a feature it did not request or receive. Dangerous ones need your consent.

What permissions are dangerous?

The dangerous group covers camera, microphone, location, contacts, calendar, phone, SMS, call logs, storage, physical activity, and nearby devices. They touch private data and need your consent. Accessibility, device admin, and overlay are special permissions with even more power.

How do I check app permissions?

Open Settings, Apps, tap the app, then Permissions to see current grants. To review before install, open the APK in App Manager or APK Analyzer, or run aapt dump permissions on a PC. The full how-to is in our permission check guide.

What is accessibility service permission?

Accessibility service lets an app read the screen and perform actions for the user, which is meant for people who need help using the device. It is also the permission banking trojans pursue, because it can read and tap through any app, including banking apps.

What is device admin permission?

Device admin lets an app lock the screen, wipe the device, and change security settings. Few consumer apps need it. A flashlight or game requesting it is a red flag. Revoke it in Settings before uninstalling an app that holds it.

What is overlay permission?

Overlay, or draw over other apps, lets an app display on top of other apps. Legitimate uses include dimmers and floating widgets. Malware uses it to draw fake login screens over banking apps, so grant it only to apps you trust with your screen.

Can I revoke permissions after installing?

Yes. Open Settings, Apps, tap the app, then Permissions, and turn off what you do not want. On Android 11 and later, unused apps lose permissions automatically. App Manager and ADB give more granular control.

What happens if I deny a permission?

The app keeps working without that capability, or it asks again when it needs it. Some apps show limited features or refuse to run without a core permission. If a non-core app refuses to work without an unrelated permission, that is a red flag.

What is usage access permission?

Usage access lets an app see which apps you use and when, plus some device-history data. Digital wellbeing and launcher apps use it. It reveals patterns about your behavior, so grant it only to apps whose function requires it.

What is install unknown apps permission?

Install unknown apps lets one app install other APKs. Android 8 and later grants it per source, not globally. Grant it to one trusted app like Files or Chrome, install what you need, then turn it off to reduce risk.

What permissions should I never grant?

Never grant SMS, accessibility, device admin, or overlay to an app with no clear need. An SMS grant enables premium-text fraud, accessibility enables screen reading, device admin enables wiping, and overlay enables fake login screens. Deny these by default.

How do permissions affect privacy?

Permissions decide what an app can learn about you. Contacts, location, microphone, and messages are the sensitive groups. Trackers combine with permissions to build a profile. Checking permissions and trackers together is how you control what an app knows.

Part of the complete guide

Are APK Files Safe? Risks, Checks & Red Flags (2026)

Also in APK safety: