AppXpose AppXpose
← All scans
MEDIUM Risk · Score 34/100

Microsoft 365

com.microsoft.office.officehubrow

Microsoft 365 is a legitimate productivity suite with strong encryption and GDPR compliance, but exhibits extensive telemetry collection, multiple ad-tech SDKs including Facebook SDK, and broad permission scope. The large app size and aggressive data collection for personalization elevate risk to medium.

34
out of 100
5
Trackers Found
4
Dangerous Permissions
9
Risk Factors
0
Known Breaches
Score Breakdown

+6
Telemetry and analytics SDKs

Microsoft first-party telemetry plus Google Analytics for usage tracking and AI training

+5
Ad-tech SDKs and behavioral profiling

AdMob, Facebook SDK, AD_ID - cross-app behavioral targeting

+4
Permission count: 51 total

High but reflects feature breadth (camera, audio, media access)

+4
Data sharing with Microsoft ecosystem

Documents, emails, contacts flow to OneDrive, Teams, Copilot AI

+3
Multidex and APK complexity

8 DEX files at 378 MB - complex but legitimate for full Office suite

+3
Freemium with aggressive upsell

Limited free tier; premium features require subscription

-6
Developer reputation and GDPR

Microsoft - regulated corporation, transparent privacy policy, GDPR-compliant

-3
Encryption and data protection

TLS in transit, AES-256 at rest, multi-factor authentication

+2
Unexpected permissions: READ_PHONE_STATE

Used by ad SDKs for device fingerprinting

Trackers

5 SDKs detected

Hidden inside the code.

Google Analytics Analytics
Google AdMob Advertising
Facebook SDK Advertising
Microsoft Telemetry Analytics
Adjust Attribution
Permissions

4 flagged

What it asks for.

medium
READ_PHONE_STATE

Device fingerprinting for ad targeting - not core to Office

medium
AD_ID

Google Advertising ID for cross-app behavioral tracking

medium
RECORD_AUDIO

Teams calls and voice notes - legitimate but sensitive

medium
CAMERA

Document scanning and Teams video - legitimate but sensitive

Scan Microsoft 365 yourself.

Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.