The average app requests 14 permissions, according to a 2025 academic analysis of 4,465 benign Android apps by Alkinoon and colleagues, drawn from the AndroZoo dataset and cross-validated against Google Play. That is nearly three times the 5-permission average Pew Research Center found in 2014, when it examined more than a million apps in the Google Play Store. The count keeps climbing because app functionality keeps expanding, and because Android's own permission taxonomy has grown to 321 distinct entries. Not every one of those 14 permissions is sensitive, but a majority now touch location, storage, or a device identifier in some form.

How many permissions does the average app request?

Average app permissions requested, 2014 versus 2025 5 14 2014 2025 average permissionsrequested per app

14 permissions is the average for a typical Android app today, based on a 2025 study that examined 5,028 apps split between 4,465 benign and 563 confirmed malicious samples. Researchers pulled the dataset from AndroZoo, the largest public archive of Android application packages, and cross-checked each entry against the live Google Play catalog to confirm the app still exists and matches its declared category.

The study, led by Ali Alkinoon and coauthors and submitted to the Journal of Cybersecurity and Privacy in August 2025, extracted 63,480 individual permission requests across five years of app releases, from 2019 through 2023. Benign apps accounted for 58,162 of those requests and malicious apps for 5,318, which is how the researchers arrived at their per-app averages: 14 for benign software, 16 for malicious software.

Two other counts are worth comparing side by side, because they measure different populations with different methods, the same way three separate trackers can report three different GDPR fine totals without any of them being wrong. Pew Research Center's landmark 2014 study, based on more than a million Play Store apps, found an average of just 5 permissions per app. NordVPN's Cybersecurity Research Lab, which focuses only on the most downloaded apps across 18 popular categories rather than a random cross-section, put the current Android average at 19 permissions in its May 2026 mobile app research.

SourceYearSampleAverage permissions per app
Pew Research Center20141,041,336 apps, all categories5
Alkinoon et al. (benign apps)20254,465 apps, 2019 to 202314
Alkinoon et al. (malicious apps)2025563 apps, 2019 to 202316
NordVPN Cybersecurity Research Lab2026103 top apps, 18 categories19

Every figure is defensible once you know what it counts: a broad, representative sample lands near 14, while a sample weighted toward feature-rich, popular apps lands closer to 19.

Why has the average climbed since 2014?

Average permissions requested per app, 2014 vs 2025 051015202014 (Pew, all apps)2025 (benign apps)2025 (malicious apps)16

Figure 1: The average has roughly tripled in a decade. Source: Pew Research Center (2014), Alkinoon et al. 2025 academic study.

The average has roughly tripled since Pew Research Center's 2014 measurement, and three forces explain most of the increase. Apps do more than they used to, phones expose more capabilities to request permission for, and Android's own permission catalog has grown alongside both.

Android's permission model now defines 321 distinct permission strings, according to Alkinoon et al.'s 2025 taxonomy, compared with 235 that Pew Research Center counted in 2014. That works out to a 36.6% increase in available permissions to request, even before accounting for how many apps actually ask for more of them. System and device management permissions alone account for 92 of the 321 entries, close to 29% of the entire taxonomy, reflecting how much finer-grained control Android now offers over background processes, storage scoping, and hardware access.

The trend is not uniform across app types either. The same 2025 study found that games and apps in Google Play's catch-all "Other" category request the broadest range of permissions, largely tied to location, network, and device management access, while apps in the Books, Music, and Travel categories request the fewest.

A decade of new capabilities, not a single bad actor, is driving the number up.

How many of an app's permissions are actually dangerous?

Android apps flagged with at least one dangerous permission 62% 38% Android apps flagged with adangerous permission, versusnone at all

62% of Android apps requested at least one permission Android classifies as dangerous, based on NowSecure's assessment of more than 378,000 apps over the twelve months ending in June 2025. Dangerous permissions are the subset that can access sensitive data or core device functions, precise location, camera, contacts, and external storage among them, and require an explicit user tap to approve rather than being granted automatically at install.

iOS looks safer by this measure but is not risk-free. Of 335,000 iOS app assessments NowSecure conducted over the same period, nearly 31,000, about 9.3%, used what Apple calls a dangerous entitlement, the iOS equivalent of a sensitive permission. Across both platforms combined, 37% of all app assessments turned up at least one risky permission or entitlement.

Zooming into the most popular apps sharpens the picture further. An analysis Cybernews conducted of the 50 most downloaded Google Play apps, cited in NowSecure's June 2025 report, found an average of 11 dangerous permissions per app in their manifest files, with gaming apps averaging just 4 and apps in the Health and Fitness, Communications, and Productivity categories asking for the most. If your business collects any of that data through a mobile app, the permissions you request need to match the disclosures in your privacy policy word for word; a privacy policy generator built around current app permission categories keeps that mapping accurate as your app's feature set changes.

Most apps carry at least one sensitive permission. The question worth asking is whether every one of them is disclosed.

Which app categories request the most unnecessary permissions?

Average unnecessary permissions requested, by app category Social networking10Navigation9Dating6Messaging5

Figure 2: Social apps request the most permissions they do not need. Source: NordVPN Cybersecurity Research Lab, mobile app research.

Social networking apps top the list, requesting an average of 10 permissions their core functionality does not require, according to NordVPN's Cybersecurity Research Lab. Navigation apps follow at 9 unnecessary permissions, dating apps at 6, and messaging apps at 5.

Across its full 2026 sample of 103 top apps in 18 categories, NordVPN found 87% of Android apps and 60% of iOS apps requested at least one permission they did not need to function. That gap between platforms mirrors a pattern this cluster keeps finding; see our breakdown of mobile app privacy statistics for how that 87% figure splits out by data type and how it compares with third-party data-sharing rates.

Unnecessary is not the same as malicious. A social app that asks for calendar access to schedule a meetup, or a navigation app that keeps background location on after a trip ends, is usually poorly scoped rather than hostile. But every unnecessary permission is still an unnecessary disclosure obligation, and an unnecessary attack surface if the app is later compromised.

The categories that request the most unneeded access are exactly the ones handling the most sensitive user data, which raises the stakes of getting the scoping wrong.

Which individual permissions do apps request most often?

Share of studied apps requesting each permission type Location37%Camera35%Photo gallery22%Microphone16%

Figure 3: Location edges out camera as the most requested permission type. Source: NordVPN Cybersecurity Research Lab, mobile app research.

Location tops the list. NordVPN's Cybersecurity Research Lab found 37% of the apps it studied request location access, followed by camera access at 35%, photo gallery access at 22%, and microphone access at 16%.

Location and camera lead for a structural reason: both permissions unlock features, maps, check-ins, photo uploads, video calls, that a large share of consumer apps genuinely offer. The gap between location's 37% and microphone's 16% roughly tracks how many mainstream app categories have a legitimate use for each capability. Nearly half of the apps NordVPN studied also requested at least one permission tied to monitoring user activity outside the app itself, a category that includes background location and cross-app tracking identifiers.

On the Android side specifically, Alkinoon et al.'s 2025 dataset confirms the same pattern at the manifest level: ACCESS_NETWORK_STATE, ACCESS_FINE_LOCATION, and ACCESS_COARSE_LOCATION were the three most frequently requested permission strings across all 63,480 extracted requests, ahead of every storage or contacts-related permission.

If you only harden the disclosure for one permission type, location is the one most apps in your category are already asking for.

How does Android decide which permissions need your approval?

Figure 4: The three-tier approval structure behind every permission prompt. Source: Android Developers documentation, permission protection levels.

Android sorts every permission into a protection level before it ever reaches a user's screen. Normal permissions, ones with minimal risk to privacy, are granted automatically at install with no prompt. Dangerous permissions, the ones covering location, camera, microphone, contacts, and similar sensitive data, require an explicit runtime approval from the user the first time the app requests them.

A smaller third tier, signature and special-access permissions, is reserved for apps signed with the same certificate as the requesting system component, or for settings a user must toggle manually outside the normal permission prompt; screen recording and accessibility services are common examples. This three-tier structure is why the 62% dangerous-permission figure from NowSecure's study matters more than a raw permission count: a 20-permission app that only touches normal-tier capabilities carries less real risk than a 5-permission app that touches three dangerous ones.

Total permission count is a rough signal. Which tier those permissions fall into is the sharper one.

What are the key milestones in app permission history?

Figure 5: A decade of platform and regulatory milestones around app permissions. Source: Pew Research Center, GDPR (Official Journal of the EU), Android Developers documentation, Apple Newsroom, Alkinoon et al. 2025.

App permission systems have tightened steadily since regulators and platform owners started treating over-permissioning as a consumer protection problem rather than a technical footnote.

The European Union's GDPR, effective 25 May 2018, was the first major regulation to require that data collection, permission requests included, be tied to a specific, disclosed purpose. Android 11, released in September 2020, introduced one-time permissions and automatically revoked access for apps left unused for months. Apple's App Tracking Transparency framework, which launched with iOS 14.5 in April 2021, forced every iOS app to ask before tracking users across other apps and websites, a permission category that barely existed as an explicit prompt before that date.

The EU's Digital Markets Act added a second regulatory layer starting in March 2024, when its obligations became enforceable against designated gatekeeper platforms, adding fresh scrutiny to how app stores handle permission and tracking disclosures. By 2025, the data in this piece, the 14-permission average and the 62% dangerous-permission rate, shows that tighter platform rules have not reduced the number of permissions apps ask for. They have mostly changed how those requests get disclosed and approved.

Regulation has made permission requests more visible, not fewer.

The Bottom Line

14 permissions is a reasonable planning number for what a typical Android app asks a user to approve today, nearly three times Pew Research Center's 5-permission average from 2014. But the average masks wide variation: popular apps in NordVPN's May 2026 sample average 19, malicious apps average 16, and the most heavily instrumented categories, social networking, navigation, health, and communications, routinely exceed both. The practical test is not the raw count, it is whether every permission you request maps to a feature you actually ship and a disclosure your users can actually find. With 62% of Android apps carrying at least one dangerous permission and 87% requesting at least one they do not need, most apps have room to cut their permission list down, and every app has room to make sure its privacy policy accounts for whatever remains.

Frequently Asked Questions

How many permissions does the average app request? The average benign Android app requests 14 permissions, according to a 2025 academic study of 4,465 apps by Alkinoon and colleagues, drawn from the AndroZoo dataset and submitted to the Journal of Cybersecurity and Privacy. That is nearly three times the 5-permission average Pew Research Center measured across 1,041,336 Google Play apps in 2014.

What percentage of apps request at least one dangerous permission? 62% of Android apps requested at least one dangerous permission, based on NowSecure's assessment of more than 378,000 apps over the year ending June 2025. On iOS, about 9.3% of 335,000 app assessments used a dangerous entitlement over the same period.

Which app categories request the most unnecessary permissions? Social networking apps request an average of 10 unnecessary permissions, followed by navigation apps at 9, dating apps at 6, and messaging apps at 5, according to NordVPN's Cybersecurity Research Lab.

Is Android worse than iOS for permission requests? Yes. NordVPN's May 2026 research found Android apps average 19 permissions versus 5 on iOS, and separately that 87% of Android apps request at least one unneeded permission compared with 60% of iOS apps.

Where the Numbers Come From

  1. Alkinoon, A., Dang, T.C., Alghuried, A., et al. (2025). "A Comprehensive Analysis of Evolving Permission Usage in Android Apps: Trends, Threats, and Ecosystem Insights." Submitted to the Journal of Cybersecurity and Privacy, August 2025. Dataset of 5,028 apps (4,465 benign, 563 malicious) from AndroZoo, cross-validated against Google Play, covering 2019 to 2023.
  2. NowSecure. (2025). "How Dangerous Mobile App Permissions Threaten Enterprise Security." Published 4 June 2025, based on assessments of 378,000-plus Android apps and 335,000 iOS apps over the prior year.
  3. Pew Research Center. (2015). "App Permissions: An Analysis of Android Phones." Published 10 November 2015, based on 1,041,336 apps analyzed between June and September 2014.
  4. NordVPN Cybersecurity Research Lab. (2026). "Mobile privacy: What do your apps want to know?" Analysis of 103 top apps across 18 categories, May 2026.
  5. Cybernews. Manifest-file analysis of the 50 most downloaded Google Play apps for dangerous permissions, cited in NowSecure's June 2025 report.

Note: All figures verified as of July 2026. The 14-permission and 19-permission averages measure different populations, a broad Android sample versus curated top apps across 18 categories, and are not directly interchangeable. Figures are refreshed at least twice a year as NordVPN, NowSecure, and academic datasets publish updates.