← Privacy & toolsaudit your android phone from your laptop in 5 minutes

audit your android phone from your laptop in 5 minutes

$getprop ro.build.version.security_patch

your phone has been quietly collecting receipts

you probably haven't checked your phone's security patch level since you bought it. you also probably have a flashlight app that wants your precise location, a pdf reader that wants your contacts, and a game that wants to read your sms messages. none of that is paranoia, that's just default android behavior nobody audits. good news: you can check all of it from your laptop in about five minutes using adb, no root required.

step 1: check how far behind you are

first thing, plug your phone into your laptop, enable usb debugging in developer options, and confirm the connection on the phone itself. then run this:

getprop ro.build.version.security_patch

this spits out a date, something like 2023-01-05. that's the last time your phone got a security patch, not an os update, a security patch. android pushes these monthly to fix actively exploited vulnerabilities. if that date is more than 2 to 3 months old, you're running on known, publicly documented holes. if it's over a year old, assume your phone is a liability and start planning a replacement or a custom rom.

step 2: see what you actually installed

stock android ships with a pile of system apps you didn't choose and mostly can't remove. to cut through the noise and see only what you actively installed, run:

adb shell pm list packages -3

the -3 flag means "third party only," so you get a clean list of apps you downloaded, minus the manufacturer bloat and core android services. scroll through it. you will find apps you forgot existed. you will find apps you installed once for a single use and never opened again. those are exactly the apps worth checking next, because an app you don't use is an app you're not watching.

step 3: check what permissions an app actually holds

the play store listing tells you what an app asks for. it doesn't tell you what it currently has, especially permissions you granted months ago and forgot about. to see the real, current state, run:

adb shell dumpsys package com.example.app

swap in the real package name from your step 2 list. the output is long, scroll to the section labeled runtime permissions. anything marked granted=true is live right now. this is where you find the flashlight app with fine location access, the calculator with microphone permission, the photo editor that can read your call log. none of that is a bug, it's just an app that asked once and you tapped "allow" without thinking about it.

step 4: take back what it doesn't need

once you've spotted a permission that makes no sense for what the app actually does, pull it back directly:

adb shell pm revoke com.example.app android.permission.ACCESS_FINE_LOCATION

this revokes that specific permission without uninstalling the app or breaking features you actually use. a flashlight doesn't need your gps coordinates to turn on an led. a pdf reader doesn't need your contacts to open a file. if revoking a permission breaks something you genuinely rely on, android will re-prompt you for it the next time the app needs it, so you're not locking yourself out, you're just removing standing access that was never required.

step 5: close the door behind you

usb debugging is a powerful mode, it's how you got all this access in the first place, and it's also an attack surface if your phone is ever plugged into a laptop or charger you don't control. when you're done auditing, go back into developer options and turn usb debugging off. don't leave it sitting enabled "just in case." it's one toggle, and leaving it on is how a phone gets quietly accessed through a compromised charging station or a borrowed cable.

the takeaway

most people will patch their laptop without a second thought and never once check the phone that holds their banking app, their photos, and their location history 24/7. you don't need to be a developer to do this, you need adb, a usb cable, and five minutes. run the patch check, list your installed apps, pull the real permissions, revoke what doesn't belong, and lock debugging back down. do this once a month and you'll actually know what's running on your phone instead of just hoping it's fine.

watch the reel ↗
the weekly drop

one command a week that makes you harder to hack.

a single tool, explained in plain english, every week. straight to your inbox.

no spam. one email a week. unsubscribe anytime.