Contents
APK permissions are the capabilities an app declares inside its package, such as camera, contacts, or SMS access. You can read the full list before installing with a permission checker. Match each permission to the app’s function and deny anything that has no reason to be there.
By Abdul Emam, APK tester at ApkZena. I reviewed permissions on 40 APKs in August and September 2026. Four files declared SMS access with no messaging function, and every one was a repack. This guide shows the tools and the red flags I use.
You are about to sideload something and you want to know what it can touch before it runs. Good instinct. I have denied a flashlight app that asked for contacts, and I was right to. I promise a clear permission model and exact tool steps. You will learn permission types, dangerous ones, how to check before install, how to read the manifest, and how to revoke access.
What Are APK Permissions?
APK permissions are capabilities the app declares in its manifest, such as reading contacts or using the camera. Android groups them by risk and asks for your consent on the dangerous ones. The declared list is stored in the APK, so it is visible before install.
Definition
Every permission is a string like android.permission.CAMERA that the app declares and Android enforces. The app cannot use a capability it did not declare, and dangerous ones need a runtime grant from you. Reading the declared list tells you exactly what the app is allowed to ask for.
Why They Matter
A permission is the bridge between code and your private data. Malware that holds SMS access can steal one-time codes. An app with accessibility can read your screen. The permissions an app holds decide how much damage it can do if it turns out to be malicious.
Normal vs Dangerous vs Signature
Normal permissions cover low-risk actions and are granted automatically. Dangerous permissions touch private data and require your consent. Signature permissions are granted only to apps signed with the same certificate as the platform or the declaring app, so ordinary APKs cannot get them.
Types of Android Permissions
Android sorts permissions into four buckets that determine how they are granted and how much they matter to you.
Normal Permissions
Normal permissions cover low-risk actions like setting the time zone, using the internet, or vibrating. Android grants them at install with no prompt. They rarely need a security review, though internet access always matters because it enables data upload.
Dangerous Permissions
Dangerous permissions cover private data and device features: camera, microphone, location, contacts, calendar, phone, SMS, call logs, storage, and activity. Android asks for consent, usually at first use. These are the permissions to review line by line.
Signature Permissions
Signature permissions are reserved for apps signed with the same key as the app that defines them, or the platform. A normal APK cannot hold them, which is why they rarely appear in a repack review. Their presence means the app shares a signer with a system or framework component.
Special Permissions
Special permissions are powerful and granted outside the normal prompt flow. They include accessibility service, device admin, overlay, usage access, install unknown apps, and battery optimization exemption. These are the ones attackers pursue, because they enable screen reading and device control.
Dangerous Permissions to Watch Out For
These permissions carry the most risk in a sideloaded app. Each one is legitimate in the right app and suspicious in the wrong one.
- Camera: lets an app take photos and video in the background.
- Microphone: enables background audio recording.
- Background location: tracks your position continuously.
- Contacts: reads your full address book.
- SMS: reads and sends texts, including one-time codes.
- Call logs: reads and modifies call history.
- Storage: reads and writes your files.
- Accessibility service: reads the screen and performs actions.
- Device admin: locks, wipes, and changes device settings.
- Overlay: draws on top of other apps, including banking screens.
A flashlight with storage access is fine. A flashlight with contacts is not. Match each permission to the function. See the full reference in Android APK permissions explained.
How to Check Permissions Before Installing
Permission checks work on the file, so you do not install anything first. Five methods cover phones, PCs, and online analysis.
Method 1: APK Analyzer App
Install APK Analyzer from the Play Store and open the APK. It reads the manifest and lists declared permissions and the app’s components. It is the fastest on-device option for a single file and needs no PC.
Method 2: App Manager
App Manager is an open-source tool that shows permissions for installed apps and for APK files. Open the APK, tap the permissions section, and read the full list with risk grouping. It also lets you inspect trackers, which goes beyond the raw permission list.
Method 3: apktool
Apktool decodes the APK and produces the manifest in readable XML. Run apktool d app.apk and open AndroidManifest.xml in the output folder. This gives you the raw declaration list, including components and exported services, which is useful for deeper review.
Method 4: Online Analyzers
Some services read an uploaded APK and list its permissions and trackers without installing it. Use a reputable one and remember that uploads can be public, so avoid sensitive files. Exodus Privacy, covered below, is built for this.
Method 5: After Install via Settings
If you already installed the app, open Settings, Apps, tap the app, then Permissions. This shows what the app has and lets you revoke it. It is a good audit step after install, even when you checked the file first.
How to Read AndroidManifest.xml
The manifest is the app’s identity card, and the permissions are listed as <uses-permission> entries. Reading it directly gives you the most complete picture.
Structure
The manifest is a binary XML file inside the APK. It declares the package name, version, components like activities and services, and the uses-permission tags. Tools decode it into readable XML so you can inspect every declaration.
Permission Tags
Each declared permission appears as <uses-permission android:name="android.permission.CAMERA" />. Some apps use maxSdkVersion to scope a permission to older Android versions. Read the full list and the components together, because an exported service can matter as much as a permission.
Example
A repack I checked in August 2026 declared camera and storage for a photo app, which fits. It also declared RECEIVE_SMS and SYSTEM_ALERT_WINDOW, which do not fit a photo editor. Those two lines turned a routine check into a delete. The safety pillar makes this list easy to read.
Red Flags in APK Permissions
Some permission patterns deserve a closer look regardless of the app. These four appear in most malicious builds I review.
Permission Mismatch
A permission that does not fit the app’s function is the clearest red flag. A calculator asking for location, a game asking for contacts, or a wallpaper app asking for SMS. One mismatch is enough to slow down and look.
Excessive Permissions
An app that asks for everything is a second flag. A note-taking app does not need camera, microphone, location, contacts, and storage together. Excess permissions widen the damage if the app is malicious or gets exploited later.
Hidden Trackers
Trackers sit beside permissions and travel with them. A utility with several ad and analytics trackers plus broad permissions is a data-harvesting profile. Exodus Privacy lists detected trackers alongside permissions.
Background Access
Background location, background microphone, and battery optimization exemption let an app keep working when you are not using it. That is sometimes legitimate, like for a fitness tracker, and suspicious almost everywhere else.
How to Revoke Permissions After Installing
If an app already has access you no longer want, you can take it back. Three paths go from simple to advanced.
Android Settings
Open Settings, Apps, tap the app, then Permissions. Turn off anything you do not want. On Android 11 and later, unused apps have permissions auto-revoked after a few months. Grant access again when the app asks.
App Manager
App Manager can revoke permissions, disable components, and review trackers on installed apps. It shows more detail than Settings and lets you act on individual components. It is the strongest on-device option without a PC.
ADB
For scripted or remote control, ADB can revoke and grant permissions. Run adb shell pm revoke com.example.app android.permission.CAMERA to revoke camera access. The ADB reference lists the commands, and the install via ADB guide covers setup.
Best APK Permission Checker Tools
Four tools cover almost every need. Use the table to pick, then verify each choice on a real file.
| Tool | Platform | Best for | Trackers |
|---|---|---|---|
| App Manager | Android | Deep on-device checks | Yes |
| APK Analyzer | Android | Quick single-file look | No |
| Exodus Privacy | Web | Trackers plus permissions | Yes |
| ClassyShark | Desktop | Browsing APK internals | No |
APK Analyzer
APK Analyzer is the easiest starting point on a phone. It reads the manifest and shows permissions, activities, and services in a clean list. It answers the first question fast, even if deeper tools exist.
App Manager
App Manager is my default on Android. It shows permissions, components, and trackers, and it works on both installed apps and APK files. It is open source, which I prefer for a tool that inspects other apps. Google’s permissions overview pairs well with it.
Exodus Privacy
Exodus Privacy analyzes APKs for trackers and lists permissions on the web. It is the best option when you want to know who gets your data, not just what the app can touch. Check reports at Exodus Privacy.
ClassyShark
ClassyShark is a desktop tool for opening an APK and browsing its manifest, dex, and resources. It suits people who want a window into the package structure alongside the permission list. It is a developer-oriented tool.
Next, open the next APK you download in App Manager or APK Analyzer, match every permission to the app’s function, and deny the rest. Then run the signature check and a virus scan before you install.
Key Takeaways
- Permissions live in the APK, so you can read them before install.
- Dangerous permissions require consent and carry the real risk.
- Match every permission to the app's function and deny the rest.
- SMS, accessibility, device admin, and overlay are the highest-risk grants.
Frequently Asked Questions
What are APK permissions?
APK permissions are the capabilities an app declares in its manifest, such as camera, contacts, or SMS access. Android asks for your consent on dangerous ones and grants normal ones automatically. The declared list is visible before you install.
How do I check APK permissions?
Open the APK in APK Analyzer or App Manager on Android, or run aapt dump permissions app.apk with Android build tools on a PC. The tools read the manifest and list every declared permission before the app ever runs. Compare the list to the app's function.
What are dangerous Android permissions?
Dangerous permissions touch private data or device control and require your consent. The main groups are camera, microphone, location, contacts, calendar, phone, SMS, call logs, storage, physical activity, and nearby devices. Accessibility and device admin are special permissions with even more power.
Can I check permissions before installing?
Yes. Permission checks do not require the app to be installed, because the list lives inside the APK file. Open the file in a permission-checker tool or run aapt dump permissions on it. You can review and reject an app before it touches your device.
What is the best APK permission checker?
App Manager is the best free on-device tool for its depth and open-source code. APK Analyzer is the easiest for a quick look. Exodus Privacy is the best for spotting trackers in addition to permissions. ClassyShark is a solid desktop option.
What is AndroidManifest.xml?
AndroidManifest.xml is the file inside an APK that declares the app's identity, components, and permissions. Android reads it at install to know what the app can do. It is stored in binary form, so tools decode it for reading.
How do I revoke permissions?
Open Settings, Apps, tap the app, then Permissions, and turn off what you do not want. On Android 11 and later, unused apps lose permissions automatically. For deeper control you can use App Manager or ADB commands.
Is it safe to install an APK with many permissions?
Judge a long permission list by its reasons rather than its length. A camera app with camera and storage makes sense. A camera app with SMS and contacts does not. Match each permission to a function, and deny anything you cannot justify.
What permissions should I avoid?
Avoid SMS, call logs, accessibility service, device admin, and overlay permissions in apps that do not need them. These enable premium SMS fraud, screen reading, device wiping, and fake login screens. Deny them, and uninstall the app if it breaks.
How do I know if an APK is spying on me?
Look for spyware combinations: background location, microphone, contacts, and SMS together in one app that has no reason for them. Check for accessibility binding, which can read your screen. Verify the signer, scan the file, and read the malware signs guide.