System app database

Package

com.google.android.networkstack.overlay

GoogleNetworkStackResOverlay

36device profiles
37observations
0user-facing hits
6 Sep 2026last seen

Guidance

Disable with caution verified 11 Sep 2026

A small resource package in Google's namespace whose label varies by device: this site records GoogleNetworkStackResOverlay, NetworkStackOverlay, NetworkStackGoogleResOverlay, or the bare package name in place of a label. It has no launcher entry, no observation here is user-facing, none is Play-eligible, its aggregated permission set holds a single entry, POST_NOTIFICATIONS, and builds are recorded between roughly 8.5 KB and 74.1 KB. This site aggregates permissions across observations rather than per build, so which builds request that permission cannot be established. The name and labels describe a Runtime Resource Overlay (RRO), which AOSP defines as a package that changes the resource values of a target package at runtime, and which cannot carry code. The labels point at the Google-signed NetworkStack module, which this site records as com.google.android.networkstack with the label "Network manager". On 34 of the 36 devices that record this overlay, this site also records that module, which is consistent with it being the overlay's target, though the target is inferred from naming rather than confirmed. On 30 of the 36 devices it is recorded alongside the AOSP-keyed overlay com.android.networkstack.overlay, so on those devices the two overlays coexist rather than one replacing the other. What an overlay of NetworkStack may set is published by the module itself. AOSP describes Network Stack as an updatable Mainline module that ensures Android can adapt to evolving network standards, naming captive portal detection and login code as an example, and its components include the DHCP client and NetworkMonitor, which tests for internet reachability, detects captive portals and validates networks. The module declares an overlayable named NetworkStackConfig, whose entries include the captive portal HTTP and HTTPS probe URLs and their list and fallback forms, the DNS probe timeout, the regular expressions used to judge whether a validation probe succeeded or failed, the default DNS servers, and DHCP client hostname options. Which of these values this package sets on any build could not be sourced. Provenance: despite the Google namespace, none of the signing certificates recorded for it here is classified as Google's. Among the observations that carry signing data, 10 distinct certificates are recorded, each classified as the device maker's own key, covering Motorola, Lenovo, OPPO, vivo, Xiaomi, NUU, OUKITEL and ANT DAO TECHNOLOGY LIMITED; eight of the ten are recorded as also signing the Android framework, a platform-level key. The package is seen across 20 device make names in this sample, including TCL, OnePlus, realme, Infinix and Blackview. Version note. Observations here run from API 30 to API 36, version names run from 12 to 15, and this site's target SDK roll-up reports 31 to 35. Those are independent roll-ups across observations rather than a per-build pairing, so they cannot say which target SDK a given device carries. AOSP documents the module it appears to accompany as updatable through Mainline. Whether the values this overlay sets have changed across Android releases could not be sourced. For Android Enterprise, EMM and kiosk use it has no identified enrolment or policy role in the sources cited here and nothing a user interacts with. If it overlays NetworkStack as its name indicates, the captive portal probe URLs are the entries worth knowing about on a managed or filtered network, since they decide which endpoint the device contacts when judging whether a network has internet access. If this package overrides them, disabling it could change the endpoints used for validation; the resulting values would depend on the module defaults and any other enabled overlays, and this package's actual overrides could not be sourced. No hardening benefit from disabling it is established by the cited sources. Where kiosk mode is stopping a captive portal login from appearing, the documented fix is to allow the captive portal login package in the EMM policy rather than to touch this package.

Package intelligence

Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.

10
signing certs
OEM-forked / varies
1
permissions
largest set observed
0.0 MB – 0.1 MB
APK size
31 – 35
target SDK
12 → 15
versions observed
10
device profiles
Declared permissions (1)

Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.

PermissionDescription
POST_NOTIFICATIONS Allows the app to show notifications

Manage on devices

ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.

Disable for the current user
adb shell pm disable-user --user 0 com.google.android.networkstack.overlay
Remove for the current user - a per-user uninstall; the APK stays on /system, so Restore re-adds it (-k keeps app data)
adb shell pm uninstall -k --user 0 com.google.android.networkstack.overlay
Re-enable
adb shell pm enable com.google.android.networkstack.overlay
Restore (re-install for the current user)
adb shell pm install-existing com.google.android.networkstack.overlay

Seen on

Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.

OEMModelAndroidProvenanceObservationsLast seen
Ant Dao Technology Limited B3 Android 14 OEM ANT DAO TECHNOLOGY LIMITED 1 18 Aug 2026
Blackview VARG Android 11 - 1 1 Sep 2025
DOOGEE S41 Max Android 13 - 2 3 Oct 2025
Fezawio F11_V_US Android 15 - 1 14 Jul 2026
Hotwav TAB R9 Pro Android 14 - 1 18 Sep 2025
Infinix Infinix X6871 Android 14 - 1 21 May 2025
Lenovo Lenovo TB-7306F Android 11 - 1 19 Jul 2025
Lenovo Lenovo TB-X6C6NBF Android 12 - 1 15 May 2025
Lenovo TB132FU Android 14 - 1 16 Jun 2025
Lenovo TB328FU Android 12 - 1 15 Sep 2025
Lenovo TB352FU Android 15 OEM LENOVO 1 6 Sep 2026
Lenovo TB570FU Android 15 - 1 17 Jun 2025
Motorola moto g - 2025 Android 16 OEM Motorola 1 14 Dec 2025
Motorola moto g14 Android 13 OEM Motorola 1 19 Dec 2025
Motorola moto g24 Android 14 OEM Motorola 1 19 Dec 2025
NUU S6707X Android 14 OEM NUU 1 12 Jan 2026
OnePlus CPH2465 Android 14 - 1 17 Jun 2025
OnePlus CPH2653 Android 16 - 1 24 Nov 2025
OnePlus HD1903 Android 12 - 1 10 Sep 2025
OnePlus KB2005 Android 14 - 1 17 Sep 2025
OPPO CPH2591 Android 15 - 1 10 Jul 2025
OPPO CPH2637 Android 15 OEM OPPO 1 2 Feb 2026
OUKITEL C59 Pro Android 15 - 1 6 Nov 2025
OUKITEL WP28 E Android 14 OEM OUKITEL 1 24 Aug 2026
realme RMX2001 Android 11 - 1 21 Aug 2025
realme RMX3627 Android 12 - 1 20 Sep 2025
Rhino T8 Android 14 - 1 17 May 2025
Smt_hk Helium Pro Android 12 - 1 19 Jul 2025
TCL 6025D_EEA Android 11 - 1 17 Sep 2025
TCL 6165H Android 13 - 1 16 Sep 2025
TCL 9466X Android 13 - 1 13 Jan 2026
TCL 9491G Android 14 - 1 26 Aug 2025
Ulefone Power Armor X11 Pro Android 12 - 1 15 Sep 2025
vivo V2550 Android 16 OEM vivo 1 21 Jul 2026
Xiaomi 21091116UI Android 13 - 1 8 Sep 2025
Xiaomi 24117RN76O Android 15 OEM Xiaomi 1 28 Dec 2025

Known labels

Locale-aware display names seen in the wild.

LabelLocaleSeen
GoogleNetworkStackResOverlay en-gb 6
GoogleNetworkStackResOverlay en-us 4
NetworkStackOverlay en-us 4
com.google.android.networkstack.overlay en-us 3
GoogleNetworkStackResOverlay es-es 2
GoogleNetworkStackResOverlay en-US 2
NetworkStackOverlay en-GB 2
NetworkStackOverlay en-gb 2
com.google.android.networkstack.overlay 2
GoogleNetworkStackResOverlay 1
GoogleNetworkStackResOverlay en 1
GoogleNetworkStackResOverlay en-GB 1
GoogleNetworkStackResOverlay en-in 1
GoogleNetworkStackResOverlay en-za-u-fw-mon-mu-celsius 1
GoogleNetworkStackResOverlay es-US 1
GoogleNetworkStackResOverlay es-us 1
GoogleNetworkStackResOverlay vi-VN 1
GoogleNetworkStackResOverlay vi-vn 1
NetworkStackGoogleResOverlay ru-ru 1
NetworkStackOverlay ja-jp 1
NetworkStackOverlay ru-ru 1
NetworkStackOverlay en 1
NetworkStackOverlay it-it 1
com.google.android.networkstack.overlay es-MX 1
com.google.android.networkstack.overlay es-mx 1
com.google.android.networkstack.overlay fr-fr 1
com.google.android.networkstack.overlay de-de 1
com.google.android.networkstack.overlay en 1
com.google.android.networkstack.overlay en-lk 1
com.google.android.networkstack.overlay en-pk 1