
audit your android phone from your laptop in 5 minutes
getprop ro.build.version.security_patchyour phone has been quietly collecting receipts
you probably haven't checked your phone's security patch level since you bought it. you also probably have a flashlight app that wants your precise location, a pdf reader that wants your contacts, and a game that wants to read your sms messages. none of that is paranoia, that's just default android behavior nobody audits. good news: you can check all of it from your laptop in about five minutes using adb, no root required.
step 1: check how far behind you are
first thing, plug your phone into your laptop, enable usb debugging in developer options, and confirm the connection on the phone itself. then run this:
getprop ro.build.version.security_patch
this spits out a date, something like 2023-01-05. that's the last time your phone got a security patch, not an os update, a security patch. android pushes these monthly to fix actively exploited vulnerabilities. if that date is more than 2 to 3 months old, you're running on known, publicly documented holes. if it's over a year old, assume your phone is a liability and start planning a replacement or a custom rom.
step 2: see what you actually installed
stock android ships with a pile of system apps you didn't choose and mostly can't remove. to cut through the noise and see only what you actively installed, run:
adb shell pm list packages -3
the -3 flag means "third party only," so you get a clean list of apps you downloaded, minus the manufacturer bloat and core android services. scroll through it. you will find apps you forgot existed. you will find apps you installed once for a single use and never opened again. those are exactly the apps worth checking next, because an app you don't use is an app you're not watching.
step 3: check what permissions an app actually holds
the play store listing tells you what an app asks for. it doesn't tell you what it currently has, especially permissions you granted months ago and forgot about. to see the real, current state, run:
adb shell dumpsys package com.example.app
swap in the real package name from your step 2 list. the output is long, scroll to the section labeled runtime permissions. anything marked granted=true is live right now. this is where you find the flashlight app with fine location access, the calculator with microphone permission, the photo editor that can read your call log. none of that is a bug, it's just an app that asked once and you tapped "allow" without thinking about it.
step 4: take back what it doesn't need
once you've spotted a permission that makes no sense for what the app actually does, pull it back directly:
adb shell pm revoke com.example.app android.permission.ACCESS_FINE_LOCATION
this revokes that specific permission without uninstalling the app or breaking features you actually use. a flashlight doesn't need your gps coordinates to turn on an led. a pdf reader doesn't need your contacts to open a file. if revoking a permission breaks something you genuinely rely on, android will re-prompt you for it the next time the app needs it, so you're not locking yourself out, you're just removing standing access that was never required.
step 5: close the door behind you
usb debugging is a powerful mode, it's how you got all this access in the first place, and it's also an attack surface if your phone is ever plugged into a laptop or charger you don't control. when you're done auditing, go back into developer options and turn usb debugging off. don't leave it sitting enabled "just in case." it's one toggle, and leaving it on is how a phone gets quietly accessed through a compromised charging station or a borrowed cable.
the takeaway
most people will patch their laptop without a second thought and never once check the phone that holds their banking app, their photos, and their location history 24/7. you don't need to be a developer to do this, you need adb, a usb cable, and five minutes. run the patch check, list your installed apps, pull the real permissions, revoke what doesn't belong, and lock debugging back down. do this once a month and you'll actually know what's running on your phone instead of just hoping it's fine.