Google Play Console自动添加权限问题:未声明却提示新增READ_PHONE_STATE权限
Hey there, this is a frustrating but common issue when updating apps on Google Play—let’s walk through the most likely causes and fixes:
1. Check for Implicit Permissions from Dependencies
Most of the time, this happens because a third-party library (like ad SDKs, analytics tools, or push notification services) you’re using has declared the android.permission.READ_PHONE_STATE permission in its own manifest. Your app’s final merged manifest will include all permissions from your dependencies, even if you didn’t add them manually.
To verify this:
- In Android Studio, open your app’s manifest file, then switch to the Merged Manifest tab at the bottom of the editor. This will show you the complete, compiled manifest with all merged permissions.
- Alternatively, run this Gradle command to generate the merged manifest file directly:
Look for the./gradlew app:mergeReleaseManifestREAD_PHONE_STATEentry in the output file (usually located atapp/build/intermediates/merged_manifests/release/AndroidManifest.xml).
2. Remove Unwanted Permissions Explicitly
If you find the permission is coming from a dependency and you don’t actually need it, you can force-remove it from your app’s manifest. Add this line to your AndroidManifest.xml, making sure you include the tools namespace in the root manifest tag:
First, add the tools namespace to your manifest root:
<manifest xmlns:android="http://schemas.android.com/apk/res/android" xmlns:tools="http://schemas.android.com/tools" package="your.app.package">
Then add the permission removal line:
<uses-permission android:name="android.permission.READ_PHONE_STATE" tools:node="remove" />
This tells the manifest merger to exclude that permission entirely from your final APK.
3. Verify Your APK’s Actual Permissions
Double-check the permissions in your signed release APK to be 100% sure. You can use the aapt tool (part of the Android SDK Build Tools) to list permissions:
aapt dump permissions your-app-release.apk
If this output doesn’t include READ_PHONE_STATE, then the issue might be a false positive from Google’s automated checks.
4. Appeal to Google Play Support
If you’ve confirmed your APK doesn’t include the permission at all, head to the Google Play Console:
- Go to your app’s App content section
- Navigate to the Permissions and features page
- Find the
READ_PHONE_STATEentry, and use the appeal option to explain that your app doesn’t use this permission. Include screenshots of your merged manifest or theaaptoutput as evidence.
Google’s support team usually responds within a few business days to resolve false positives like this.
内容的提问来源于stack exchange,提问作者Marcus J.Kennedy

