What Is Android's Accessibility Service, and Why Do Some Apps Ask for It?
Android's Accessibility Service is a framework that lets an app observe what is on screen and perform actions on the user's behalf. It was built so people with disabilities can use their phones, and it is one of the most powerful permissions on the device, which is exactly why it deserves a careful look before you allow it.
- The Accessibility Service lets an app see on-screen events and, if configured, read window content and perform gestures.[1]
- Google Play limits who may call themselves an accessibility tool and requires everyone else to show a prominent disclosure and get consent.[2]
- Legitimate non-assistive uses include parental-control app blockers and narrow rule-based automation.
- Be wary of any app with no accessibility or blocking purpose that asks for it, and prefer apps installed from Google Play.
What the Accessibility Service is for
The AccessibilityService API exists to build assistive tools. Typical examples are screen readers that speak what is on screen for people with visual impairments, switch-based input for people with motor impairments, and voice control.
To do that job, an accessibility service needs two abilities that ordinary apps do not have: it receives events about what changes on screen, and, depending on how it is configured, it can read the contents of windows and tap, swipe or type for the user. The service's configuration file sets attributes such as canRetrieveWindowContent and canPerformGestures.[1]
How it works, and why it is sensitive
- It is opt-in and manual. The user must switch a service on in Settings → Accessibility. Android shows a warning describing what the service will be able to see and do.
- It spans every app. A running service can receive events from other apps' screens, not just its own.
- It is configured in the manifest. The service declares which event types it wants, and whether it may retrieve window content or perform gestures, in an accessibility-service configuration file.
That reach is the point for a screen reader, and the risk for everything else.
Legitimate uses beyond disability access
Some non-assistive apps use the API for a narrow, disclosed purpose:
- Parental-control and app-blocker apps that detect which app is in the foreground so they can enforce limits.
- Rule-based automation that performs a fixed action when a known trigger occurs.
As an example from our own product: Paxio's app blocker uses the service to detect the app currently in the foreground, and to recognize Android's own "App info" and "Deactivate device admin" screens so removing the app asks for the parent's PIN. It does not read the content of other apps. The app shows an explanation of exactly this before sending the parent to the Settings screen.
How the permission is abused
Because the service can read screens and press buttons, malicious apps have used it to capture what a user types or sees, to tap through permission prompts without the user noticing, and to approve their own installation steps. Banking trojans are the classic example.
Red flag: an app that has no obvious accessibility or blocking purpose, such as a flashlight, wallpaper or cleaner app, asks you to enable an accessibility service. Do not enable it.
Android adds friction for apps installed from outside the store: since Android 13, a sideloaded app's request to use accessibility is blocked by default until the user explicitly allows restricted settings for that app, as reported ahead of the Android 13 release.[3] We cover the sideloading side in our guide to what sideloading is.
What Google Play requires
Google Play's AccessibilityService API policy sets the guardrails:[2]
- Only services designed to help people with disabilities can declare themselves accessibility tools with the
isAccessibilityToolattribute. - Apps that are not accessibility tools must show a prominent in-app disclosure and get the user's consent before the service is enabled.
- Apps using the API must complete a Permission Declaration Form and be approved by Google Play.
- Automation must serve a narrow, clearly understood purpose. Deterministic, rule-based automation is allowed; autonomous planning and execution of actions is prohibited for non-accessibility tools.
The same principle appears in OWASP's MASVS-PLATFORM controls, which expect apps to interact with the platform and other apps securely and with minimal exposure.[4]
A quick checklist before you allow it
- Does the app clearly need it? A screen reader or an app blocker does. A game does not.
- Did the app explain why before sending you to Settings, in plain language?
- Where did you get it? Prefer apps from Google Play over sideloaded files.
- Read the warning dialog. Android lists what the service can observe and do.
- Review it later. You can switch a service off under Settings → Accessibility at any time.
You can also see whether an app declares an accessibility service by uploading its APK to the APK analyzer: services guarded by the BIND_ACCESSIBILITY_SERVICE permission appear in its exported-components table.
Frequently asked questions
Is it safe to give an app accessibility permission?
Only if the app has a clear, disclosed reason that needs it, such as a screen reader or an app blocker, and you got it from a trusted source. The permission is powerful, so treat unexplained requests as a red flag.
Can an accessibility service read my passwords?
Depending on its configuration, a service can read on-screen content, which is why malicious ones are dangerous. Android masks password fields from many accessibility events, but you should still enable the service only for apps you trust.
How do I turn an accessibility service off?
Open Settings, go to Accessibility, choose the service and switch it off. Doing so stops the app from observing the screen.
Why does a parental-control app need accessibility access?
To detect which app is currently open so it can apply app limits and blocks. Reputable apps explain this before asking and limit what they read.
What is the isAccessibilityTool flag?
It is an attribute in a service's metadata that declares it a genuine accessibility tool. Google Play's policy reserves it for services designed to help people with disabilities, and those apps are exempt from the prominent-disclosure requirement.
What is TalkBack?
TalkBack is Android's built-in screen reader and the most familiar example of an accessibility service. It speaks what is on screen for people with visual impairments.
Is an accessibility service the same as device admin?
No. They are separate Android features. Device admin lets an app enforce device policies such as screen locking, while an accessibility service observes the screen and performs actions.
How can I see which apps have accessibility access?
Open Settings and go to Accessibility. The exact menu names vary by manufacturer, but you will find a list of installed accessibility services that you can open and switch off.
Do I need to enable accessibility for a sideloaded app?
Only if the app has a real reason to need it. Sideloaded apps hit a "restricted setting" block first, and you should treat any unexplained request as a warning sign.
- Create your own accessibility service — Android Developers — service configuration attributes such as canRetrieveWindowContent and canPerformGestures.
- Use of the AccessibilityService API — Play Console Help — isAccessibilityTool, prominent disclosure and automation rules.
- Android 13 Restricted setting feature blocks sideloaded apps — Chrome Unboxed (July 8, 2022) — independent reporting on the Android 13 restricted-setting change; secondary source.
- OWASP MASVS — MASVS-PLATFORM — secure interaction with the platform and other apps.