vix.ing · top · new · best · stats · spec

Silent Consent, Persistent Risk: Android Permission Groups and Custom Permissions

2026/05/26 by Olawale Amos Akanji, Manuel Egele, Gianluca Stringhini · 1 voice
Computer Science · #Advanced Malware Detection Techniques #Android (operating system) #Android malware #Confidentiality #Malware #Opt-in email #Password #Permission #Security and Verification in Computing #Software Testing and Debugging Techniques #Usability #cs.CR

paper · pdf · doi:10.48550/arxiv.2605.27667

openalex publication_date 2026/05/26 · arxiv published 2026/05/26 · arxiv updated 2026/05/26 · openalex created_date 2026/05/29 · openalex updated_date 2026/07/28

Abstract

Android's permission system is designed to balance usability with informed consent, yet two legacy mechanisms still undermine that balance in Android 16: (i) permission groups that silently auto-grant new permissions within a group after a user's initial approval, and (ii) normal-level custom permissions that are auto-granted at install and enable cross-app access with no user visibility. We conduct a longitudinal analysis of 19.3 million APKs spanning 5.97 million unique apps (distinct package identifiers) from the AndroZoo repository, combined with on-device validation on Android 16. Among 2,244,575 multi-version apps, 381,026 (17%) silently gain permissions within already-granted groups. Using VirusTotal detections with primary threshold t=20, apps flagged as malware expand within groups at a higher rate than benign apps (odds ratio = 1.35, p < 0.001); the association holds across every tested threshold and concentrates in permission-heavy apps (OR = 2.06 in the top quartile). We also identify 307 cross-developer normal-custom-permission pairs that expose contacts, SMS, location, authentication credentials, user identity, and medical records to unrelated apps without any user prompt. A lightweight prototype built on public Android APIs recorded 23 silent expansion events across 13 apps during a 96-day single-device pilot, showing that update-time transparency is reachable without OS modification. Our results show that consent erosion persists despite a decade of platform hardening and affects apps ranging from obscure utilities to widely deployed and pre-installed software.

Citations

Discussions

Related