Which messaging app takes the most limited approach to permissions on Android?

Messaging apps handle sensitive conversations, contacts, and media, and their behavior on a device varies in ways that affect privacy. An analysis of Android versions of Messenger, Signal, and Telegram shows that differences in permissions, background activity, and system exposure shape how much data each app can access and how often it communicates.

Android permissions privacy risks

Permissions define access to device and user data

The three apps take different approaches. Telegram has the lowest total number of permissions at 71, though it includes the highest number of dangerous permissions at 25. Signal has 72 permissions, including 19 dangerous ones.

“Messenger, by contrast, requests the most (87) permissions in total, of which 24 are dangerous, and further stands out for requesting the most vendor specific “unknown” permissions,” researchers said.

These unknown permissions are not part of the standard Android system and are typically used either for communication between app components or for interaction with vendor-specific services.

Core messaging features rely on sensitive permissions

Access to sensitive resources such as contacts, camera, microphone, location, storage, and calendar is part of how messaging apps deliver core features.

Contact permissions support address-book integration, storage access enables media exchange, and camera, microphone, and location access are used for voice messages, video calls, and live location sharing.

Telegram and Messenger extend this access further with system-level permissions such as CALL_PHONE, SYSTEM_ALERT_WINDOW, and account management, which support functions like in-app calling and overlay interfaces.

Signal takes a more limited approach, omitting phone-call control, overlay windows, background location, calendar access, and package installation rights.

Configuration and network handling differences

Static analysis using the Mobile Security Framework (MobSF), a tool used to scan mobile apps for potential security issues, shows how these apps are set up and where problems can appear.

All three fall into the same “medium risk” range, meaning they include a mix of findings that could matter depending on how the apps are used. Messenger stands out for having far more flagged issues than the others, especially in the medium-severity range.

One difference appears in how network traffic is handled. Telegram allows cleartext connections by default through the usesCleartextTraffic setting, which leaves its traffic open to interception. Signal uses encrypted connections by default and allows limited cleartext traffic only for certificate checks.

Messenger’s findings are more varied. These include world-writable files and WebViews with remote debugging enabled, both of which can allow data tampering or inspection at runtime. A certificate-related warning was examined more closely and turned out to be a false positive, since Messenger uses its own TLS implementation with built-in certificate validation.

The apps also differ in how they rely on external services. Messenger includes third-party SDKs such as Google Analytics and Mapbox. Signal and Telegram do not declare third-party trackers. All three use Firebase Cloud Messaging to deliver notifications, and the analysis did not find any leakage of sensitive data through that channel.

Where data travels

Messenger exchanges most of its traffic with North America, with additional connections in South America and Europe.

Telegram’s traffic is concentrated in Europe, with smaller volumes in the United States, Asia, and Oceania. Signal’s traffic is also centered in Europe, with additional connections in the United States and Asia.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Sony And Honda’s PlayStation EV Won’t Hit The Road

Tomohiro Ohsumi/Getty Images Sony and Honda have killed off the upcoming electric car, Afeela EV, before it could even get off the production line. It appears that the PlayStation-adjacent vehicle is a victim of Honda’s overhaul of its current position in the EV market going forward. On

Iran claims attack on Oracle data center in Dubai; says: IRGC’s navy command …

Iran’s IRGC says 37th wave of attacks launched against Israel, heavy missiles used Iran’s Islamic Revolutionary Guard Corps (IRGC) has reportedly claimed that it has struck a data center of American tech company Oracle in Dubai. According to a report in AlJazeera, IRGC’s navy command claims it launched an attack on a data center belonging

Native Apps? It’s a Trap! ⭐️

Maybe it’s because I’ve been covering Microsoft professionally for over 30 years, I don’t know, but when it comes to this company and its promises for Windows, I have these out-of-body experiences sometimes, these flashes that take me out of the moment. I had one when it announced Recall at the Copilot+ launch event in

2 EV Stocks That Are Too Cheap to Ignore Right Now

The electric vehicle (EV) market cooled off, especially in the U.S., over the past few years. That slowdown — along with higher interest rates, increased competition, and reduced government subsidies — chilled the industry and deflated the valuations of many high-flying EV stocks. But according to Grand View Research, the global EV market could still

The 12 hours of Whipple evidence that made a judge side with detainees again: non-working phones, treatment like ‘animals’

In January, dozens of detained immigrants crowded into a Whipple building holding cell where a toilet overflowed with feces, urine caked the floor and the phone didn’t work. That’s according to “J.J.B.,” a 20-year-old refugee from Venezuela who testified before a Minnesota judge this month. He described “begging” to contact an attorney for help getting

[OPINION] Traffic Apps Care About Algorithms, Not Neighborhoods

As a longtime Bridge Street resident, Werner Liepolt has a front-porch view of traffic — including the vehicles that apps like Waze send past his house. He writes: Take a look at Westport the way a navigation algorithm does. I-95: Thursday, March 26, 9 p.m. It sees not a collection of neighborhoods — but a

Ahead of Greek Social Media Ban, Parents Desperate to Separate Children From Phones

By Lefteris Papadimas and Renee Maltezou ATHENS, April 2 (Reuters) – Greek mother Georgia ⁠Efstathiou ⁠has tried everything to loosen the grip ⁠that social media has on her 14-year-old son: heart-to-heart talks; internet-free time; confiscating his phone. Arguments ​flare as she fights the allure of his screen and its videos and messages. Now, Efstathiou may

Electric Vehicle Busbar Market to Reach USD 4.7 Billion by 2030 ,

Stratview Research The Electric Vehicle Busbar Market is projected to reach nearly USD 4.7 billion by 2030, growing at a CAGR of around 13.0% during 2025-2030. The market was valued at approximately USD 2.5 billion in 2025, reflecting strong expansion driven by rapid electrification trends. Electric vehicle busbars are critical components that distribute high current

EV Battery Market worth $251.33 billion in 2035 |

Delray Beach, FL, April 01, 2026 (GLOBE NEWSWIRE) — According to MarketsandMarkets™, the global EV battery market is projected to reach from USD 91.93 Billion in 2024 to USD 251.33 Billion in 2035, at a CAGR of 9.6%. This growth is being fueled by the rapid shift of automakers and fleet operators toward electrification, along

Verizon sues Chilmark over rejected cell coverage upgrades

A Verizon truck driving down Beach Road in Tisbury. —Eunki Seonwoo Verizon, one of the largest telecommunications companies in the nation, has sued Chilmark after the town denied upgrades by the cellular company that would have expanded cell coverage to its customers.  The federal lawsuit, filed by Verizon on March 16 in the U.S. District

What’s going on with Donut Lab?

In January, a Finnish-Estonian startup proclaimed it had developed a truly solid state battery, a holy grail for the technology industry. Donut Labs’ cell wasn’t just solid state, however. It claimed it was made from cheap and easily available materials, would charge to full in a few minutes and last for hundreds of years. If

Samsung Galaxy Watch Upgrade Adds Blood Pressure Tracking

Summary created by Smart Answers AI In summary: Tech Advisor reports that Samsung Galaxy Watch users in the US received FDA-approved blood pressure tracking, extending to older models like the Galaxy Watch 4. This health monitoring upgrade requires monthly calibration with an arm cuff and Wear OS 4 with Android 12+ for accurate readings. The

Pregnancy Tracking and Postpartum Care Apps Market Growth

Report Overview The Global Pregnancy Tracking and Postpartum Care Apps Market size is expected to be worth around US$ 1945.4 Million by 2035 from US$ 356.3 Million in 2025, growing at a CAGR of 18.5% during the forecast period 2026-2035. In 2025, North America led the market, achieving over 38.5% share with a revenue of

Middle East Electric Vehicle Market Surpasses USD 7.6 Billion

Middle East electric vehicle market grows with policy support, charging expansion, and rising EV adoption across region expansion Delhi, India – March, 2026 – Ken Research released its strategic market analysis titled “Middle East Electric Vehicle Market Report Size, Share, Growth Drivers, Trends, Opportunities & Forecast 2025-2030,” revealing that the current market size is valued

0
Would love your thoughts, please comment.x
()
x