Package
com.samsung.aasaservice
SecurityPolicy
Guidance
A Samsung platform component with two different names attached to it, neither of which Samsung explains. Devices in this database report the label "SecurityPolicy", while Samsung's own Knox Common Criteria mode application lists, which inventory the software preinstalled on a certified model, list the same package as "AASAservice". Samsung publishes no description of the component and does not expand the abbreviation anywhere we could find, so this note does not expand it and does not infer a purpose from either name. In particular, do not read the device-reported label as documentation that this is what enforces security policy on a Galaxy device: nothing we found supports that, and Knox policy enforcement is documented separately. What can be stated is the provenance recorded here. It is preinstalled and Samsung-signed with certificates that also sign the framework, and it has no launcher entry in our sample. Its permission set is large, up to 71 permissions, and mixed in character. Some entries are consistent with a privileged background service: RECEIVE_BOOT_COMPLETED, SCHEDULE_EXACT_ALARM and USE_EXACT_ALARM, INTERNET and ACCESS_NETWORK_STATE, POST_NOTIFICATIONS, INTERACT_ACROSS_USERS and INTERACT_ACROSS_USERS_FULL, and REAL_GET_TASKS, which is a signature or privileged permission that exposes what is running on the device. Others are Samsung-defined and point at Samsung subsystems rather than at the platform: READ_SCPM and WRITE_SCPM, com.samsung.android.asksmanager.permission.BIND_ASKS_MANAGER, com.samsung.android.sm.permission.BIND_DEVICE_SECURITY, com.sec.android.SYSTEM_FILE_ACCESS and two private access token permissions. The set also includes a long block of bind permissions for Samsung's on-device AI services under com.samsung.android.intellivoiceservice, com.samsung.android.aicore, com.samsung.android.scs and com.samsung.android.visual.cloudcore. This site aggregates permissions across all observations of a package rather than reporting them per build, so which builds declare which of these cannot be established from the record. What any of that does in practice is not published, and the mixture of a security-sounding label with AI service bindings is exactly the kind of thing that should not be guessed at. Version note: this package has clearly changed, and the version history is the evidence. Samsung's Common Criteria lists record version 6.4 on the Galaxy S7 LTE (Android 8), 12.0 on the Galaxy S20+ 5G (Android 10) and 15 on the Galaxy S21+ 5G (Android 11), all in a plain incrementing series. This database's sample then spans 23 through to 3.0.05.0, so the numbering was reset onto a new 1.x, 2.x, 3.x line partway through, with target SDKs from 31 to 36 and package size rising from roughly 82 KB to 5.7 MB. A version scheme reset alongside a seventyfold size range is a strong hint that something about the component changed substantially, though on its own it does not establish what. Which Android or One UI release any such change landed in, and what the component does differently as a result, could not be sourced. No observation in our sample is marked Play-eligible, so it ships and updates with firmware on the devices we have seen. For Android Enterprise, EMM and kiosk fleets, no source was found identifying it as an enrolment, policy or compliance dependency, and no source describes what it does at all. That absence is the finding. It is a privileged, network-capable, boot-starting component that can see running tasks and act across users, on a device where the vendor documents neither its function nor its data handling. If a deployment needs to account for every privileged vendor component, this one cannot be signed off from public documentation and is a reasonable thing to raise with Samsung or your device supplier directly. Because its function could not be established, no disable recommendation is given here, and anyone considering acting on it should treat that as an experiment on a single device rather than a fleet change.
- Galaxy S21+ 5G (SM-G996B, Android 11) Common Criteria mode application list - Samsung Knox Documentation →
- Galaxy S20+ 5G (SM-G986U1, Android 10) Common Criteria mode application list - Samsung Knox Documentation →
- Galaxy S7 LTE (SM-G930R4, Android 8) Common Criteria mode application list - Samsung Knox Documentation →
- Package provenance for com.samsung.aasaservice - Android System App Database →
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, but 2 different certificates appear across the fleet, so OEMs ship their own builds of it. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (508 packages, 10196 observations).
- Its largest observed manifest declares 71 permissions: 1 runtime (user-granted), 5 signature or system-level, 4 install-time and 61 vendor or uncatalogued.
- APK size ranges from 0.1 MB to 5.5 MB across the reporting device profiles, so the build differs substantially between them.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (71)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_LOCAL_NETWORK |
- |
ACCESS_NETWORK_STATE |
Allows the app to view information about network connections such as which networks exist and are connected. |
INTERACT_ACROSS_USERS |
Signature or privileged system permission. |
INTERACT_ACROSS_USERS_FULL |
Signature-level system permission, for platform-signed apps. |
INTERNET |
Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. |
POST_NOTIFICATIONS |
Allows the app to show notifications |
REAL_GET_TASKS |
Signature or privileged system permission. |
RECEIVE_BOOT_COMPLETED |
Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the phone and allow the app to slow down the overall phone by always running. |
SCHEDULE_EXACT_ALARM |
This app can schedule work to happen at a desired time in the future. This also means that the app can run when you\u2019re not actively using the device. |
SUBSTITUTE_NOTIFICATION_APP_NAME |
Signature or privileged system permission. |
USE_EXACT_ALARM |
This app can schedule actions like alarms and reminders to notify you at a desired time in the future. |
com.samsung.aasaservice.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
- |
com.samsung.android.aicore.permission.BIND_DOWNLOAD_SERVICE |
- |
com.samsung.android.aicore.permission.BIND_ON_DEVICE_SERVICE |
- |
com.samsung.android.aicore.permission.BIND_WALLPAPER_SERVICE |
- |
com.samsung.android.aicore.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.samsung.android.asksmanager.permission.BIND_ASKS_MANAGER |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.SYSTEM_BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.SYSTEM_SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.ai.tts.permission.BIND_TEXT_TO_SPEECH |
- |
com.samsung.android.intellivoiceservice.ai.tts.permission.BIND_TEXT_TO_SPEECH_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.aitranslator.permission.BIND_TRANSLATION |
- |
com.samsung.android.intellivoiceservice.aitranslator.permission.BIND_TRANSLATION_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.common.permission.CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.common.permission.SYSTEM_CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.permission.BIND_CLASSIFICATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_CONFIGURATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_CORRECTION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_CORRECTION_SERVICE_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.permission.BIND_EMOJI_AUGMENTATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_EXTRACTION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_FORMAT_CONVERSION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_GENERIC_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_NOTES_ORGANIZATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SMART_CAPTURE_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SMART_COVER_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SMART_REPLY_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SMART_REPLY_SERVICE_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SUGGESTION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SUGGESTION_SERVICE_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SUMMARIZATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SUMMARIZATION_SERVICE_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.permission.BIND_TONECONVERT_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_TONECONVERT_SERVICE_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.permission.BIND_TRANSLATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_USAGE_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_WRITING_COMPOSER_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_WRITING_COMPOSER_SERVICE_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.samsung.android.permission.READ_SCPM |
- |
com.samsung.android.permission.WRITE_SCPM |
- |
com.samsung.android.privateaccesstokens.PAT_TOKEN_PERMISSION |
- |
com.samsung.android.privateaccesstokens.SERVER_CHANGE_PERMISSION |
- |
com.samsung.android.scs.ai.asr.permission.BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.scs.ai.asr.permission.SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.scs.ai.asr.permission.SYSTEM_BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.scs.ai.asr.permission.SYSTEM_SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.scs.ai.image.permission.BIND_IMAGE_SERVICE |
- |
com.samsung.android.scs.ai.image.permission.IMAGE_PROVIDER |
- |
com.samsung.android.scs.ai.suggestion.permission.SUGGESTION_PROVIDER |
- |
com.samsung.android.scs.ai.text.permission.TEXT_PROVIDER |
- |
com.samsung.android.scs.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.samsung.android.sm.permission.BIND_DEVICE_SECURITY |
- |
com.samsung.android.visual.cloudcore.permission.BIND_DOWNLOAD_SERVICE |
- |
com.samsung.android.visual.cloudcore.permission.BIND_IMAGE_EDITOR_SERVICE |
- |
com.samsung.android.visual.cloudcore.permission.BIND_PORTRAIT_SERVICE |
- |
com.samsung.android.visual.cloudcore.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.sec.android.SYSTEM_FILE_ACCESS |
- |
com.sec.spp.permission.TOKEN_c9a020e24cacdea98cc69024340df4e14fcc192d5ea363ab3c8648be2d8678fff6769d6f337dbc1ca0205d7128c5f6220f9aac400fb4383130e2936b4f7b6c08c6988a83691438c37c01adca730d466ab67c042d2aea96c8227bd66ef819d7c317aa329924b720144a040212c77de36e24fb843082faea9f697b469f0ac07e9f |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A057G | Android 15 | OEM Samsung | 1 | 8 Aug 2026 |
| Samsung | SM-A125F | Android 12 | OEM Samsung | 1 | 21 Jan 2026 |
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A515F | Android 13 | - | 1 | 30 Jun 2025 |
| Samsung | SM-A528B | Android 13 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 16 | OEM Samsung | 1 | 29 Jul 2026 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | OEM Samsung | 3 | 12 Sep 2026 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-F971B | Android 17 | OEM Samsung | 1 | 18 Sep 2026 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G766B | Android 16 | OEM Samsung | 1 | 5 Sep 2026 |
| Samsung | SM-G780F | Android 13 | OEM Samsung | 1 | 29 Dec 2025 |
| Samsung | SM-G973U | Android 12 | OEM Samsung | 2 | 10 Jun 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-M315F | Android 12 | - | 1 | 2 Feb 2026 |
| Samsung | SM-N950U1 | Android 9.0 | - | 1 | 20 Aug 2025 |
| Samsung | SM-N986B | Android 13 | - | 9 | 17 Jul 2025 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S731B | Android 16 | OEM Samsung | 1 | 11 Aug 2026 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S908U | Android 16 | OEM Samsung | 2 | 17 Sep 2026 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 17 Sep 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-S948U | Android 16 | - | 1 | 9 Sep 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-T976B | Android 13 | - | 1 | 21 Jul 2025 |
| Samsung | SM-X200 | Android 14 | - | 1 | 27 Aug 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
| Samsung | SM-X910 | Android 14 | - | 1 | 26 Jun 2025 |
| Samsung | SM-X910 | Android 15 | - | 1 | 12 Sep 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| SecurityPolicy | en-gb | 26 |
| SecurityPolicy | en | 20 |
| SecurityPolicy | en-us | 18 |
| SecurityPolicy | it-IT | 5 |
| SecurityPolicy | nl-nl | 4 |
| SecurityPolicy | de-de | 3 |
| SecurityPolicy | en-nl | 3 |
| AASAservice | es-us | 2 |
| SecurityPolicy | es-ES | 2 |
| SecurityPolicy | it-it | 2 |
| SecurityPolicy | 2 | |
| SecurityPolicy | en-GB | 2 |
| SecurityPolicy | es-es | 2 |
| AASAservice | fr-FR | 1 |
| AASAservice | fr-dz | 1 |
| AASAservice | es-US | 1 |
| AASAservice | nl-nl | 1 |
| AASAservice | en-us | 1 |
| AASAservice | fr-fr | 1 |
| SecurityPolicy | ru-ru | 1 |
| SecurityPolicy | cs-CZ | 1 |
| SecurityPolicy | cs-cz | 1 |
| SecurityPolicy | en-US | 1 |
| SecurityPolicy | en-au | 1 |
| SecurityPolicy | es-us | 1 |
| SecurityPolicy | fr-fr | 1 |
| SecurityPolicy | pl-PL | 1 |
| SecurityPolicy | pl-pl | 1 |