Conversation

Replying to
It's still possible to update privileged apps out-of-band and add new privileged permissions. The new privileged permissions just won't be granted until the OS is updated to a version with them included in the static whitelist.
1
2
Replying to and
One of the issues that this mitigates is the third party arbitrarily expanding their privileged permissions. They could release an update expanding it to the whole set of available privileged permissions on the device. It makes it so that they need permission from the OS first.
1
2
Replying to and
There's also no whitelisting for regular permissions requested by these apps, only the permissions that require them to be a priv-app to receive. It doesn't impact normal bundled apps that go in /system/app rather than /system/priv-app or permissions granted via signatures alone.
1
2
Show replies