Google Play elevated Privilege Abuse policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps that cross Android security boundaries or interfere with security controls.

Google prohibits code that breaks the app sandbox, abuses elevated privileges, or disables core security protections. Preventing users from stopping or uninstalling an app can also trigger this category.

What to check

Audit privileged commands, device administration, access to other apps’ credentials, and dependencies that claim to bypass Android restrictions. Check for changes to SELinux or other platform protections.

Review release-only paths and device-specific behavior. An operation failing on your newest test phone doesn’t establish that the code is harmless on every supported device.

How to address the rejection

Remove the bypass or abusive operation. Implement legitimate functionality through supported Android APIs and their permission model. Remove bundled tools whose purpose is to defeat those boundaries.

Verify stop and uninstall behavior alongside the feature that prompted the privileged access. If you believe an enterprise management capability was misclassified, provide the specific authorized management context and observed behavior. General claims that the app needs administrator access won’t answer a finding about abuse.

Messages this guide can help with

Elevated Privilege Abuse; Elevated Privilege Abuse policy violation; Elevated Privilege Abuse rejection; Elevated Privilege Abuse denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access