Tor Browser
Tor Browser for Android is built on Firefox, and it shows in the bytecode: 9 verified scans on 9 devices find Sentry crash-reporting classes plus Firebase and Google Sign-In signatures - all inherited from the Mozilla codebase, not added by the Tor Project. The manifest even carries a com.adjust.preinstall read permission, another Firefox leftover. The Tor Project ships these components disabled, but static analysis cannot verify configuration, only presence, so we report what is in the APK. Notable on the permission side: QUERY_ALL_PACKAGES, which allows enumerating every installed app.
Read from the bytecode.
Presence is not activity: Tor Project builds have Mozilla telemetry and crash reporting switched off, and nothing here touches your browsing anonymity, which comes from the Tor network itself. But the finding is a useful reminder that forks inherit their parent's code mass - an APK this sensitive still contains Google and Sentry class trees it never calls. If you verify builds yourself, this is what you will see and why.
This is static analysis of the APK bytecode installed on real devices: it proves which SDK classes and manifest permissions ship in the app, not what the app transmits at runtime. Traffic analysis is a different measurement.
Hidden inside the code.
What it asks for.
Can enumerate every installed app - unusually broad for a browser, inherited from the Firefox manifest
Read hook for Adjust preinstall partners - Firefox inheritance, functionless in the Tor context
WebRTC and web features - expected for a browser, gated behind prompts
Can trigger app installs - for APK downloads through the browser
Keep reading.
The False Negative Problem: Why Most Spyware Scans Miss What Matters
Most Android spyware detection tools check the wrong things. Here's why 73% of privacy violations hide in plain sight an...
The Privacy-First App Stack: What I Actually Use Instead of the Defaults
Real alternatives to tracker-heavy apps tested over 18 months. Specific recommendations for messaging, email, maps, and ...
Similar risk profiles.
Scan Tor Browser yourself.
Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.