A photo editing app asks for your contacts. A flashlight wants your location. A calculator needs camera access. You’ve seen this. You probably shrugged and tapped “Allow” because the alternative was not using the app at all.
Here’s the number that matters: the average Android app in 2026 requests 8.4 permissions at install time, up from 6.0 in 2023. That’s a 40% increase in three years. Some of this is legitimate. Most of it is not.
Why developers over-permission their apps
The honest answer is because they can. Android’s permission model lets developers ask for anything, and most users will grant it rather than abandon the install. There’s no penalty for requesting access you don’t strictly need.
Three categories explain most over-permissioning. First, lazy dependencies. Developers pull in third-party libraries that come bundled with permission requests. A single ad SDK might require location, storage, and phone state access. The app developer never explicitly decided to ask for those permissions. They just inherited them from the package they imported.
Second, feature creep without cleanup. An app adds social sharing two years ago, requests contacts permission, then removes the feature but never removes the permission declaration from the manifest file. Nobody notices. The permission stays.
Third, future-proofing greed. Why request permissions only when you need them? Just ask for everything upfront. Maybe you’ll build a feature later that uses the camera. Maybe you’ll want to track users more precisely. Better to have the access already granted than to re-prompt users and risk a denial.
The fourth category is the quiet part: data collection infrastructure. Apps request permissions they don’t need for functionality because those permissions unlock valuable data streams. Location tracking. Contact graph scraping. Photo metadata harvesting. This isn’t a bug. It’s the business model.
What over-permissioning actually costs you
Every unnecessary permission is a door you’ve left unlocked. Not just for the app developer, but for every tracker and SDK embedded in that app. When you grant storage permission to a weather app, you’re not just letting the weather app read your files. You’re letting every analytics library, ad network, and data broker inside that app do the same.
The average over-permissioned app on Android contains 4.2 third-party SDKs with access to at least one permission the app’s core functionality doesn’t require. A photo filter app that asks for contacts permission might never touch your contacts itself, but the Facebook SDK embedded inside it absolutely will.
There’s also the breach surface. Apps with excessive permissions are higher-value targets for attackers. A compromised flashlight app with camera, microphone, and storage access is a surveillance toolkit. A compromised flashlight app with only flashlight access is just a broken flashlight.
The math is brutal. If you have 50 apps installed and 30 of them have one unnecessary permission, you’ve opened 30 attack vectors that serve zero functional purpose. You’ve traded actual security for imaginary convenience.
The permission request pattern that should make you suspicious
Watch for apps that request all their permissions at install time with no explanation. Legitimate apps ask for permissions contextually. A maps app requests location when you first try to navigate. A messaging app asks for contacts when you try to invite someone.
Over-permissioned apps dump the entire permission request on you during onboarding. They hope you’ll tap through quickly. They bank on permission fatigue. By the time you see the seventh permission prompt, you’re not reading anymore. You’re just trying to get to the app.
Here’s the test: if an app requests a permission before you’ve tried to use any feature that would require it, that’s a red flag. Camera access before you’ve tapped a camera button. Contacts before you’ve opened any social feature. Location before you’ve used any location-based function.
The only exception is permissions required for the app to launch at all. A camera app can reasonably ask for camera permission upfront. A navigation app needs location from the start. But a news reader asking for your microphone? That’s not an exception. That’s a data grab.
What you can actually do about this
Android 13 and later let you deny permissions and still use apps, with degraded functionality. This is your best tool. Install the app, deny everything, then grant permissions only when the app complains it can’t complete a specific action.
Some apps will refuse to run at all without certain permissions. That’s a decision point. Ask yourself: does this app really need this access, or is the developer holding functionality hostage to collect data? If a recipe app won’t work without your location, the answer is obvious.
Use Android’s permission manager to audit what you’ve already granted. Settings, Privacy, Permission Manager. Sort by permission type. Look at which apps have location access. How many of them actually need it? Revoke aggressively. If an app breaks, you can always grant it back.
For apps you can’t avoid, consider permission toggling. Grant the permission only when you’re actively using the feature that needs it, then revoke it immediately after. Yes, this is tedious. Yes, it’s absurd that users should have to do this. But it works.
The nuclear option is to simply not install over-permissioned apps. If a calculator asks for six permissions, find a different calculator. There are always alternatives. The surveillance economy survives because users tolerate it.
The permissions arms race isn’t slowing down
App developers have learned that users will grant almost anything if prompted at the right moment. Permission requests keep expanding. The 40% increase from 2023 to 2026 will look modest by 2029.
The solution isn’t better permission models, though those would help. The solution is users who actually say no. Every denied permission is a small act of resistance against an industry that treats your phone like a data extraction device you happen to use for communication.
Audit your apps. Revoke excess permissions. Stop installing things that demand access they can’t justify. The permission creep stops when we stop granting permissions.