What Is ADB (Android Debug Bridge)? What It Does and Why Parents Should Know
ADB, the Android Debug Bridge, is a command-line tool that lets a computer talk to an Android device: install apps, copy files, open a shell and read logs. It is essential for developers and security testers, and it only works when someone switches on a setting that is hidden by default.
- ADB connects a computer to an Android device over USB, or wirelessly on Android 11 and higher.[1]
- It needs "USB debugging" enabled in Developer options, which is hidden by default and requires you to authorize each computer.[1]
- Common uses: install an APK, pull an app's files off a device, view logs and list installed packages.
- Keep debugging off unless you are using it, and never approve a computer you do not recognize.
What ADB is
The Android Debug Bridge is a versatile command-line tool in the Android SDK. It has three parts: a client you type commands into, a server that runs on your computer, and a daemon that runs on the device.[1] You can use it to run commands on a device, move files, install and uninstall apps, and collect diagnostic information.
How a device connects
Over USB
To use ADB over USB, you must turn on USB debugging in the device's system settings, under Developer options. On Android 4.2 (API level 17) and higher the Developer options screen is hidden by default and has to be revealed first.[1] Android Studio's own device-setup instructions say the same.[2]
Wirelessly
Android 11 (API level 30) and higher support deploying and debugging wirelessly with ADB, so the device does not have to stay plugged in.[1] You enable Wireless debugging in Developer options and pair the computer with the device.
Authorization
The first time a computer connects, the device asks you to allow it, and you can revoke these ADB authorizations later in Developer options.[1] That prompt is the main safeguard: a computer you did not approve cannot control the device.
Commands people actually use
adb devices # list connected devices
adb install app.apk # install an APK from the computer
adb shell pm list packages # list installed package names
adb shell pm path com.example.app # find where an app's APK lives
adb pull /path/on/device/base.apk app.apk # copy a file to the computer
adb logcat # stream the device log
The pair of pm path and pull is how you copy an installed app's APK off a phone so you can inspect it. Our APK analysis guide walks through that step by step.
The security risks
- It gives deep access. An authorized computer can open a shell on the device, install apps and read data that normal apps cannot. Only authorize computers you control.
- It bypasses store checks. An app installed with
adb installnever passes through an app store's review or age rating. See what sideloading is. - Wireless debugging widens the exposure. Android has you allow it per network, and an "always allow on this network" option makes that network a trusted one where the device reconnects automatically.[1] Only do that on a network you control.
- A forgotten setting stays on. Debugging remains enabled until someone turns it off, so switch it off when you are finished.
Never tap "Allow" on a USB debugging prompt that appears when you did not plug into your own computer, such as a public charging station.
What parents should know
A child who enables Developer options and USB debugging can pair a computer and install apps that never went through the store, or inspect and change settings. Most children never touch this, but it is worth knowing that the option exists, that it is off by default, and that it is a deliberate, multi-step action rather than something that happens by accident.
If you suspect a device was changed, check Settings for Developer options and review the list of authorized computers. A device that has also been rooted is a larger concern; see our rooting guide.
How testers use ADB
Security researchers use ADB to get apps and data off devices they own and to run tests. OWASP's Mobile Application Security Testing Guide builds many of its Android techniques around it.[3] If you are new to this, start with static analysis of an APK you pulled, which never runs the app.
Frequently asked questions
What does ADB stand for?
ADB stands for Android Debug Bridge. It is a command-line tool in the Android SDK that lets a computer communicate with an Android device.
Is USB debugging safe to leave on?
It is safer off. Debugging lets an authorized computer control the device, so turn it off when you are not using it and never authorize a computer you do not recognize.
How do I enable Developer options?
Developer options is hidden by default on Android 4.2 and higher. The usual way to reveal it is to open Settings, go to About phone and tap the build number several times; the exact path varies by manufacturer.
Do I need to root my phone to use ADB?
No. ADB works on an unrooted phone once USB debugging is enabled. Rooting is a separate, much deeper change that ADB does not require.
Can I use ADB without a cable?
Yes, on Android 11 and higher, through Wireless debugging. You enable it in Developer options and pair the computer with the device on the same network.
How do I install an APK with ADB?
Connect the device, confirm it appears in "adb devices", then run "adb install app.apk". The app installs without going through an app store, so only install files you trust.
How do I copy an app's APK from my phone?
Run "adb shell pm path
Is ADB the same as sideloading?
Installing an app with ADB is one way to sideload. Sideloading simply means installing outside a store; ADB is a tool that can do it, along with many other things.
How do I revoke ADB access?
Open Developer options and use "Revoke USB debugging authorizations" to forget every approved computer, then turn USB debugging off.
- Android Debug Bridge (adb) — Android Developers — client/server/daemon design, USB debugging, wireless debugging on Android 11+, authorizations.
- Run apps on a hardware device — Android Studio — enabling USB debugging in Developer options.
- OWASP Mobile Application Security Testing Guide (MASTG) — Android testing techniques built around adb.