Google Apps Abuse Sensitive Permissions Without User Consent
Google's own apps often ask for permission to access sensitive user data without fully disclosing how it will be used. A recent analysis has uncovered three key areas where Google's apps are overly aggressive in their requests for permission: precise location, physical activity/body sensors, and nearby devices.
The first issue lies with precise location, which Google's own apps rarely dial back even after the initial request. The Google app, Maps, and Photos all use this access to support a wide range of features, from delivering locally relevant Assistant notifications to powering Timeline entries. While these features are useful, they often go beyond what users expect when granting permission for precise location.
Google's non-fitness apps also ask for physical activity/body sensor access, which is typically associated with health and fitness tracking. The Google app itself requests this permission to detect driving or commuting patterns, while Maps uses it to infer transportation mode for more accurate directions. This accumulation of data across multiple apps can create a detailed picture of user movement and routine.
Finally, the nearby devices access is often granted without realizing that the permission doesn't expire after the initial cast session ends. YouTube, Google Photos, Chrome, and Google Home all continue scanning for nearby devices indefinitely, which can raise concerns about data privacy and security.