Open the app drawer on a Galaxy S24 and scroll past the folder Samsung labels “Samsung.” You’ll find AR Zone, a 180MB bundle of AR Emoji and AR Doodle tools most owners open once, during setup, by accident. A few rows down sits Global Goals, a United Nations partnership app that tracks progress on 17 sustainability targets and has been preinstalled on Galaxy devices since 2018. Neither app was requested. Both are still there. And both are signed with privileges that a random app from the Play Store could never touch.
That last part is the story nobody tells about Samsung’s bloatware. It’s not really about clutter. It’s about signing keys.
what these apps actually are
AR Zone (package name com.samsung.android.arzone) bundles the camera-based AR features: AR Emoji, AR Doodle, deco pic, the animated stickers that show up in the camera app. It requests CAMERA, RECORD_AUDIO, and storage access, which is defensible given what it does. It also ships Firebase Analytics and Samsung’s own internal telemetry SDK (SAMI, Samsung Analytics and Metrics Intelligence), which is less defensible for a feature most people use for thirty seconds during a demo.
Global Goals (com.samsung.globalgoals) is stranger. It’s a co-branded app with the UN Development Programme, designed to nudge users toward donating and tracking SDG progress. It’s ad-supported through Google’s AdMob, which means it requests location access for ad targeting, the same location access a donation-tracking app has no functional reason to need. It has fewer than 50,000 reviews on the Play Store version, which tells you how many people engage with it voluntarily versus how many just have it sitting on a device they bought.
the permission math doesn’t match the use case
Here’s the part that should bother you more than the storage footprint. AR Zone requests 11 permissions for a camera filter app. A standalone camera filter app on the Play Store, built by an indie developer with none of Samsung’s device access, typically requests 4 to 6. Global Goals, an app whose entire function is displaying a progress dashboard, requests location, storage, and network state, permissions a static infographic app should never need.
Individually these look like rounding errors. Permission creep is the default posture of the entire Android ecosystem now, not a Samsung-specific sin. What makes these two apps different is context: they didn’t earn their way onto your phone by being useful enough that you searched for them and installed them. They arrived pre-granted trust because of where they came from, not what they do.
why they’re actually there
Preinstall deals are a real line item. OEMs get paid, directly or through revenue-share, to ship certain apps by default. Global Goals doesn’t generate ad revenue that matters to Samsung’s bottom line at scale, but it’s cheap reputational currency: a phone maker gets to point at a UN partnership in its sustainability reporting. AR Zone exists because Samsung wants a homegrown answer to Apple’s Memoji, whether or not you asked for one.
None of that is illegal or even unusual. What’s unusual is the delivery mechanism. Many of these apps update through the Galaxy Store, not the Play Store, which means they skip Google Play Protect’s scanning pipeline entirely. Samsung runs its own vetting, but it’s not subject to the same public disclosure requirements, and update cadence is inconsistent. AR Zone’s changelog shows gaps of 7 to 9 months between security-relevant updates on some carrier variants. For an app with camera and microphone access, that’s a meaningfully long window.
the part that actually matters: signing
Most third-party apps run in a sandbox with permissions you grant explicitly. System apps signed with Samsung’s platform key can operate with elevated trust: shared user IDs, access to system settings, the ability to talk to other privileged processes without the same permission prompts a Play Store app would trigger. This is by design, it’s how OEMs build integrated features. But it also means a vulnerability in a low-value app like AR Zone doesn’t stay contained to AR Zone. Researchers have documented privilege escalation paths in Samsung system apps before (the 2023 disclosure involving a Knox-adjacent component being one example), where a bug in an unimportant-seeming app became a bridge to something that mattered.
That’s the actual risk calculus with apps nobody asked for. It’s not that AR Zone is spying on you today. It’s that it’s sitting on your phone with more structural trust than apps you deliberately chose, running code that gets patched less often, doing a job almost nobody uses.
what you can reasonably do
You can disable both apps from Settings, App info, even if you can’t fully uninstall them on every carrier variant. Disabling removes their background processes and blocks their network calls, which is most of what matters. Check App Ops (via Settings > Apps > special access, or a tool like the hidden permission manager on One UI) and revoke location from Global Goals specifically, since that permission serves the ad network, not the feature. If your device shows Galaxy Store as the update source for either app, check its last update date manually. If it’s north of six months, that’s worth knowing before you decide how much trust to extend it.
The deeper fix isn’t something you control from Settings. It’s a disclosure problem: OEMs should be required to publish update cadence and permission justification for preinstalled system apps the same way they publish spec sheets. Until that’s mandatory, the burden sits with you to notice that the app you never opened is still the one with the most access.