For you and your family

Dangerous app permissions on Android: which ones scammers use

The Android permissions scammers abuse most are Accessibility, SMS, notification access, display over other apps, install unknown apps and device admin, along with remote-access apps like AnyDesk. Check them under Settings, remove access from any app you do not fully trust, and never grant them because a caller asked.

By the Secuvexa team, I.T. Experts, Gujarat · Updated

The Android permissions scammers misuse most are Accessibility, SMS, notification access, display over other apps (overlay), install unknown apps and device admin, plus remote-access apps such as AnyDesk or TeamViewer QuickSupport. Together they let a fake app or a caller read your OTPs, see your screen, tap buttons for you and stop you from uninstalling it. Check which apps have these permissions today, remove access from anything you do not recognise, and never grant them because someone on a call told you to.

Paths below are for recent Android versions (13, 14 and 15) on most phones. Samsung, Xiaomi, Vivo, Oppo, Realme and others rename menus slightly, so if you cannot find something, use the search bar at the top of Settings.

Dangerous permissions at a glance

PermissionWhat a scammer can do with itWho genuinely needs it
AccessibilityRead everything on screen, tap and type for you, approve paymentsScreen readers, some password managers, launchers
SMSRead and forward your OTPs and bank alertsYour default messaging app
Notification accessRead OTPs and messages in notificationsSmartwatch and wearable apps
Display over other appsShow a fake login screen on top of your real bank appChat bubbles, screen filters
Install unknown appsSilently add more malicious appsYour Play Store (built in); almost nothing else
Device adminStop you from uninstalling the app, lock the phoneWork profile / company device management, Find My Device
Remote access / screen sharingSee your screen live, sometimes control itIT support you called yourself

Accessibility: the most dangerous permission

Accessibility services were built for people with disabilities. An app with this access can, as Google's own help page puts it, "read content on your screen and interact with apps on your behalf". That is exactly what banking malware wants.

Check it: Settings → Accessibility → look under Downloaded apps or Installed apps/services. Any app turned on there that is not a tool you deliberately set up should be switched off and uninstalled.

Since Android 13, apps installed from outside an app store are blocked from turning on Accessibility and notification access unless you go to the app's info page and choose Allow restricted settings (Google: restricted settings). If a caller or a "KYC app" asks you to tap Allow restricted settings, stop. That warning exists to protect you.

SMS and notification access

Your bank OTPs arrive by SMS and show up in notifications. A malicious app with either permission can forward them to a fraudster, who then completes a transaction or takes over your WhatsApp.

  • SMS: Settings → Security & privacy → Privacy → Permission manager → SMS (path from Google's permission help). Only your messaging app should be allowed.
  • Notification access: Settings → Apps → Special app access → Device & app notifications (called Notification access on many phones). Keep only your smartwatch or apps you clearly recognise.

Display over other apps (overlay)

Overlay lets an app draw on top of other apps. Malware uses it to show a fake login page over your real banking app, or to hide what is happening behind a "Please wait" screen. Check at Settings → Apps → Special app access → Display over other apps (also called Appear on top). Switch it off for anything you do not recognise.

Install unknown apps

This permission lets an app (for example WhatsApp, Chrome or a file manager) install other APK files. Scam APKs sent as "KYC update", "electricity bill" or "wedding invitation" files depend on it. Check at Settings → Apps → Special app access → Install unknown apps, and set every app to Not allowed unless you have a specific reason.

Device admin apps

Device admin rights let an app lock the screen or wipe the phone, and an active admin app usually cannot be uninstalled until you remove those rights. Malware uses this to stay on your phone. Check at Settings → Security & privacy → More security & privacy → Device admin apps (on some phones it is under Apps → Special app access). Normally you will see only Find My Device or your company's management app.

Screen sharing and remote-access apps (AnyDesk, TeamViewer QuickSupport)

AnyDesk, TeamViewer QuickSupport and similar apps are legitimate tools that IT teams use every day. The problem is a stranger asking you to install one. A fake "bank officer", "customer care" or "refund executive" says they will help you, but once connected they can watch you type your UPI PIN and read your OTPs. Gurugram Police noted that criminals have started misusing tools like AnyDesk and TeamViewer for fraud, and Rajasthan Police's October 2026 advisory says people must never install remote-access apps at the request of strangers.

No bank, UPI app, telecom company or government office will ask you to install a screen-sharing app. If you did, disconnect from the internet, uninstall it and change your banking passwords from a different device.

Also be careful with screen sharing inside WhatsApp video calls. Never share your screen with someone you do not know.

Loan apps and harassment

Many illegal instant-loan apps ask for contacts, photos and storage, then use them to threaten and shame borrowers by messaging their family and friends. The rules are clear on what a genuine lender should not do:

If a loan app is harassing you, do not pay more money under threat. Keep screenshots, report at cybercrime.gov.in or 1930, and you can also complain about unauthorised lenders on RBI's Sachet portal, which RBI pointed borrowers to in its warning about unauthorised lending apps.

How to check all app permissions in 5 minutes

  1. Open Settings → Security & privacy → Privacy → Permission manager. Tap SMS, Contacts, Call logs, Files and Location, and remove anything odd.
  2. Open Settings → Accessibility and turn off any downloaded app you did not set up on purpose.
  3. Open Settings → Apps → Special app access and review Display over other apps, Install unknown apps, Notification access and Device admin apps.
  4. Open Settings → Apps → See all apps. Uninstall apps you do not remember installing, especially "update", "KYC", "bill", "support" or "invitation" apps.
  5. Open the Play Store → your profile → Play Protect and run a scan.

If an app will not uninstall, remove its device admin rights first, then try again. If your phone behaves strangely after installing an APK, consider backing up photos and doing a factory reset, and inform your bank.

How Secuvexa Mobile helps

Secuvexa Mobile for Android reviews your installed apps and highlights risky permissions such as Accessibility, SMS, overlay, unknown sources and remote-access apps, with plain-language advice on what to remove. You can also share a suspicious link or message to the app to check it. It does not read your SMS automatically, and it cannot guarantee your phone will never be hacked. Think of it as an extra layer of protection alongside the habits above. There is a 7-day free trial.

हिंदी में: कौन सी परमिशन खतरनाक है?

Accessibility, SMS, Notification access, "दूसरे ऐप्स के ऊपर दिखाएं" (overlay), Unknown apps install और Device admin परमिशन सबसे खतरनाक हैं। कोई भी अनजान व्यक्ति फोन पर AnyDesk या TeamViewer डाउनलोड करने को कहे तो मना कर दें। Settings में जाकर देखें कि किन ऐप्स के पास ये परमिशन हैं और अनजान ऐप्स को हटा दें।

Frequently asked questions

Which Android permission is the most dangerous?

Accessibility is the most powerful, because an app with it can read what is on your screen and tap buttons for you. Only a few trusted apps, such as screen readers or password managers, genuinely need it.

Is AnyDesk or TeamViewer a virus?

No. They are legitimate remote-support apps used by IT teams. The danger is a stranger asking you to install one, because it lets them see your screen, including OTPs and banking apps. Uninstall it if a caller asked you to install it.

How do I see which apps can read my SMS?

On most Android phones, go to Settings, then Security and privacy, then Privacy, then Permission manager, and tap SMS. Exact names vary by phone brand, so you can also search for Permission manager in Settings.

Can a loan app access my contacts and photos?

RBI digital lending guidelines say lending apps should not access files, media, contact lists or call logs, and Google Play has barred personal loan apps in India from accessing photos and contacts since 2023. An app demanding these is a warning sign.

Does Secuvexa Mobile stop all malicious apps?

No app can promise that. Secuvexa Mobile reviews your installed apps and highlights risky permissions such as accessibility, SMS, overlay, unknown sources and remote-access apps, so you can decide what to remove. It is an extra layer of protection.

This guide is general information, not legal advice. If you have lost money to fraud, call 1930 immediately or report at cybercrime.gov.in.