A factory reset feels like a clean slate. It isn't. Everything that shipped with your phone's firmware — the carrier apps, the OEM "optimizers," the stub services nobody remembers installing — comes right back, because none of it was ever in /data to begin with. It lives in the system image, and a wipe only touches user data.
This is Part 3 of a three-part series on Android app safety:
- Criteria for deciding whether to install an Android app
- The history of malware that slipped past Play Store security
- Auditing your existing and preinstalled apps (this post)
In the first two parts we talked about vetting apps before you install them. This one is about the apps you never chose at all.
Why preinstalled apps deserve extra scrutiny
An app sitting in /system/priv-app isn't just another entry in your app drawer — it plays by different rules:
- It ships with OEM/carrier trust baked in. Pre-granted permissions, a system UID, access to privileged APIs that a normal downloaded app can't even ask for.
- You can't just uninstall it. Not without root, a firmware reflash, or the ADB trick further down.
- The update-hijack problem. Some OEMs ship a thin stub APK at the factory, and the real functionality downloads later — from a third-party vendor who keeps their own signing key. That means an update pushed through Play months after you bought the phone still inherits all the original system privileges. What was a one-time OEM review becomes an open-ended channel for someone else's code.
- Apps degrade over time. Peel Smart Remote is the textbook example — it went from a legitimate firmware integration to full-screen ads, spam redirects, and lock-screen modification, all through ordinary app updates.
- Factory reset genuinely does not help. Preinstalled apps live in the system partition and come back after every wipe. Researchers treat them as a distinct threat class for higher-risk users — ad SDKs quietly harvesting data, code that's hard to analyze, developers nobody's ever heard of.
If that sounds abstract, the research backs it up with real numbers. FIRMSCOPE, a static-analysis study presented at USENIX Security 2020, scanned 331,342 preinstalled apps across 2,017 firmware images from more than 100 vendors. It turned up 850 unique privilege-escalation vulnerabilities — present in 77% of the firmware images analyzed — and 92% of those vulnerabilities traced back to vendor-added code rather than stock Android.
That's not a one-off either. Kryptowire, working under a Department of Homeland Security grant, found vulnerabilities across 25 Android models (11 of them sold by major US carriers) — including flaws that let preinstalled apps wipe a device's data or lock the owner out entirely. And in 2021, Microsoft's 365 Defender team disclosed four high-severity CVEs in a carrier-preinstalled framework from mce Systems — bugs in apps that, true to form, couldn't be fully removed without root.
Step-by-step audit
1. List everything installed — including system apps
Go to Settings → Apps → See all apps → ⋮ → Show system. Scroll through with intent. You're looking for:
- Apps you don't recognize by name or icon
- A calculator, flashlight, or "optimizer" app you never installed (classic bloat, and sometimes classic malware)
- Anything with a generic Android icon and a vague, one-word name
2. Check permission hotspots
For each app that gives you pause, go to Settings → Apps → [app] → Permissions. Flag anything holding:
- Accessibility — this is powerful. It can read screen content and simulate taps. Legitimate uses: password managers, screen readers. Nothing else needs it.
- Device admin / device owner — can lock, wipe, or erase the device. Only your MDM or a genuine device-manager app should hold this.
- Install unknown apps — should only ever be your browser or file manager, and only temporarily.
- SMS / Call log — almost never justified outside your default Phone or Messages app.
- Always-on location for a utility app that has no business needing it.
3. Identify the app's origin
Settings → Apps → [app] → (menu) → App details in store
- Opens a Play listing → it's Play-distributed and will get updates through normal channels.
- No listing → it's a firmware app, installed by the OEM or carrier directly. Pull the package ID with
adb shell pm list packages, then search"<package>" vulnerabilityto see what's already known about it.
4. Check for admin and overlay abuse
- Settings → Security → Device admin apps — disable anything you don't recognize.
- Settings → Accessibility — disable any service you can't account for.
- Settings → Special app access → Display over other apps — unused grants here are a classic setup for ad-overlay phishing.
5. Disable what you can't uninstall
Settings → Apps → [app] → Disable (if the option is grayed out, try "Uninstall updates" first, then Disable). This is safe for ordinary bloatware — manufacturer app stores, demo modes, carrier apps you'll never open.
6. Advanced: ADB removal for user 0 (no root required)
adb shell pm list packages -s # list system packages
adb shell pm uninstall -k --user 0 com.example.bloat # remove for the current user
-kkeeps the app's data, and the removal is reversible: a factory reset oradb shell cmd package install-existing <pkg>brings it back.- Never remove:
com.android.phone,com.android.systemui, your launcher,com.google.android.gms(Play services),com.android.webview, your keyboard/IME, orcom.android.settings. Pulling any of these can leave your phone in a genuinely bad state. - Community bloatware lists exist — the Pixel junk-remover gist is a good example — but verify every package against your own device before running anything from a list you didn't write yourself.
7. Check update channels
In Play Store → Manage → Installed, look at each system app: is it updating through Play (Google-reviewed, reasonably current) or stuck at whatever version shipped with the firmware (updates only via full OTA)? A stub app that updates from the OEM's own store rather than Play is higher risk — weaker review, and you're trusting the vendor's update pipeline directly. Worth a quick search to see whether the vendor still actively maintains it.
8. Ongoing hygiene
- Monthly, scan Settings → Apps for anything new you didn't put there yourself.
- Pay attention to Play Protect notifications, especially "app removed" or "removed from Google Play" alerts — here's what Play Protect actually does.
- After buying a used or new phone, audit before you sign into anything financial.
- Keep the OS patched: Settings → System → System update.
Red-flag summary for preinstalled apps
- Requests SMS reading or contact upload on first boot
- An unsigned or unknown developer behind something labeled a "system utility"
- Accessibility or device-admin access granted by default, with no prompt
- Aggressive advertising coming from a system-level app
- No Play listing and no OTA updates for years — abandoned privileged code is a real risk; Black Duck found a critical RCE in two abandoned remote-control apps with a combined two million installs
- A carrier or OEM "optimizer" with background connections to domains you don't recognize
Sources
- App security best practices — AOSP
- ElcomSoft — Android preinstalled apps & update hijack (2026)
- FIRMSCOPE paper — USENIX Security 2020 (PDF)
- Kryptowire/DHS — 25 firmware models vulnerable (BleepingComputer, 2018)
- Microsoft/mce Systems CVEs (Security Affairs, 2022)
- CISSecure — dangers of preinstalled apps · TechCrunch coverage
- GitHub gist — example ADB bloatware removal list
- Use Google Play Protect (Google support)
- Android Police — pulled-app warning & abandoned-app RCE research
Part 1: 10 Criteria Before You Tap Install · Part 2: Play Store Malware History
Last updated: October 2026.