Subscribe to the Non-Human & AI Identity Journal
Home Glossary Governance, Ownership & Risk Dangerous Permission
Governance, Ownership & Risk

Dangerous Permission

← Back to Glossary
By NHI Mgmt Group Updated August 2, 2026 Domain: Governance, Ownership & Risk

A dangerous permission is an operating-system entitlement that grants access to sensitive device capabilities or data such as camera, microphone, location, storage, or messages. It becomes a governance issue when the requested access exceeds the app’s approved purpose or continues without adequate oversight.

Expanded Definition

A dangerous permission is not inherently malicious. It is an operating-system level entitlement that can be legitimate for one app and excessive for another, depending on purpose, context, and duration. In mobile and desktop environments, the risk emerges when an application requests access to camera, microphone, location, storage, contacts, messages, accessibility services, or other sensitive capabilities that are not necessary for its stated function. Definitions vary across vendors and app ecosystems, but the security principle is consistent: permission scope should match the business purpose and be reviewed over time.

For security teams, the distinction matters because dangerous permissions can create a durable attack path after installation. A single overbroad grant may enable surveillance, data exfiltration, privilege abuse, or lateral movement if the app is compromised. The issue is closely related to governance, consent, and least privilege, and it aligns conceptually with control objectives in NIST SP 800-53 Rev 5 Security and Privacy Controls. The most common misapplication is treating a permission prompt as a one-time user choice, which occurs when organisations fail to re-evaluate access after the app’s purpose, data handling, or threat exposure changes.

Examples and Use Cases

Implementing dangerous permission governance rigorously often introduces user friction and review overhead, requiring organisations to weigh application functionality against the risk of overcollection or misuse.

  • A messaging app requests microphone and camera access for video calls, but the same access remains enabled even when the feature is unused.
  • A retail app asks for location access, but continuous background tracking is not needed for store lookup or order fulfilment.
  • A file-sharing app receives storage access, yet the entitlement is broader than required and exposes unrelated personal documents.
  • An internal business app requests contacts or messages, creating a privacy concern because the business case does not justify those datasets.
  • A third-party app with accessibility permissions can read screen content and interact with the interface in ways that exceed user expectations, a pattern frequently addressed in mobile risk guidance and identity-adjacent app review processes.

Authoritative mobile security guidance such as the OWASP Non-Human Identity Top 10 is not about mobile permissions directly, but it reinforces the broader governance idea that powerful access should be tightly scoped, monitored, and revoked when no longer needed.

Why It Matters for Security Teams

Dangerous permissions matter because they turn ordinary applications into high-value trust decisions. If entitlement review is weak, a benign app can become a collection point for sensitive data, and a compromised app can inherit capabilities that should never have been granted broadly. This creates a governance gap between application approval, privacy review, and operational monitoring.

Security teams should treat permission management as part of access governance, not just app onboarding. That means validating whether a requested permission is essential, time-bound, and auditable, then revoking it when the use case changes. It also means aligning mobile and endpoint policy with data minimisation expectations and internal control libraries, including NIST SP 800-53 Rev 5 Security and Privacy Controls. Dangerous permissions become especially important where apps interact with identity data, messaging, or device sensors, because those surfaces can expose both personal information and authentication workflows. Organisations typically encounter the real cost only after a privacy incident, a compromised endpoint, or an audit finding reveals that an overbroad permission remained active long after the original business need had ended.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-01Defines access governance outcomes for controlling who and what can access assets.
NIST SP 800-53 Rev 5AC-6Least privilege control directly limits excessive permissions and overbroad access.
OWASP Non-Human Identity Top 10Highlights the need to scope powerful identities and access narrowly across systems.

Review app permissions as access outcomes and ensure each entitlement matches a documented business need.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org