Package
com.sec.android.RilServiceModeApp
Service mode RIL
Guidance
Labelled "Service mode RIL", this is a Samsung-signed system package with no launcher entry, recorded as not user-facing on every observation here. RIL is the Radio Interface Layer, the telephony layer documented in AOSP's core connectivity material, so the name places this app on the modem and telephony side of Samsung's service and engineering tooling. It is the package already named, without explanation, in this site's note on com.sec.android.app.servicemodeapp: Samsung ships more than one service-mode component and does not document the split between them. What can be established beyond the name is its declared permission set, which is consistent with a privileged telephony test tool: MODIFY_PHONE_STATE, READ_PRIVILEGED_PHONE_STATE, WRITE_APN_SETTINGS, CHANGE_NETWORK_STATE, SET_DEBUG_APP, CLEAR_APP_USER_DATA, DEVICE_POWER and SYSTEM_ALERT_WINDOW, together with keystring permissions belonging to com.sec.android.app.factorymode, com.sec.android.app.hiddenmenu and com.sec.android.app.servicemodeapp. Those declarations are consistent with the dialler keystring family documented elsewhere on this site, but they record what this package declares rather than an established runtime relationship with those components. No published vulnerability naming this component was found in the CVE record, and Samsung publishes no functional documentation, so this note does not guess at the screens it presents. Version note. Samsung's application lists record it at version 9 on Android 9-era Galaxy S10+ firmware and 11 on Android 11-era Galaxy S20 FE and S20 Ultra firmware, and this site records builds from 12 through to 17, so the version has tracked the Android major version across five data points; that is Samsung's apparent convention rather than a documented rule. One version-linked detail is worth flagging: the permissions aggregated across observations here include android.permission.SATELLITE_COMMUNICATION, which the platform manifest defines as allowing an application to communicate over satellite and grants only to system or privileged apps. That indicates satellite-related test surface in at least some builds, but which build or Android release introduced it could not be sourced. The package is observed from API 28 through API 37 with no sign of being superseded. For Android Enterprise, EMM and kiosk use, the guidance matches the rest of this family. Its reach into APN settings and phone state is exactly the kind of surface a dedicated device should not expose, and where a build also makes service-mode screens reachable from the dialler that compounds it, so control it through the app allowlist and verify by trying to break out of the finished kiosk rather than starting from package removal. Samsung does not document what depends on it, so disabling is rated caution.
- RIL refactoring (Radio Interface Layer) - Android Open Source Project →
- core/res/AndroidManifest.xml (android.permission.SATELLITE_COMMUNICATION) - Android platform source →
- Galaxy S10+ LTE (G975F) application list - Samsung Knox CC Mode documentation →
- Galaxy S20 FE 5G (G781B) application list - Samsung Knox CC Mode documentation →
- Galaxy S20 Ultra 5G (G988W) application list - Samsung Knox CC Mode documentation →
- How do I prevent users from escaping kiosk (lock task) mode? - Jason Bayton →
- Package provenance for com.sec.android.RilServiceModeApp - Android System App Database →
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, but 2 different certificates appear across the fleet, so OEMs ship their own builds of it. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (508 packages, 10196 observations).
- Its largest observed manifest declares 26 permissions: 2 runtime (user-granted), 13 signature or system-level, 4 install-time and 7 vendor or uncatalogued. The signature/system share marks it as a privileged component, not an ordinary app.
- APK size ranges from 0.1 MB to 2.6 MB across the reporting device profiles, so the build differs substantially between them.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (26)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_CHECKIN_PROPERTIES |
Signature or privileged system permission. |
ACCESS_COARSE_LOCATION |
This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. |
ACCESS_FINE_LOCATION |
This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. |
ACCESS_NETWORK_STATE |
Allows the app to view information about network connections such as which networks exist and are connected. |
CHANGE_CONFIGURATION |
Signature or privileged system permission. |
CHANGE_NETWORK_STATE |
Allows the app to change the state of network connectivity. |
CLEAR_APP_USER_DATA |
Signature-level system permission, for platform-signed apps. |
DEVICE_POWER |
Signature-level system permission, for platform-signed apps. |
FOREGROUND_SERVICE |
Allows the app to make use of foreground services. |
MODIFY_PHONE_STATE |
Signature or privileged system permission. |
MOUNT_UNMOUNT_FILESYSTEMS |
Signature or privileged system permission. |
READ_PRIVILEGED_PHONE_STATE |
Signature or privileged system permission. docs ↗ |
SATELLITE_COMMUNICATION |
Signature or privileged system permission. |
SET_ACTIVITY_WATCHER |
Signature-level system permission, for platform-signed apps. |
SET_DEBUG_APP |
Signature or privileged system permission. |
SYSTEM_ALERT_WINDOW |
This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear. |
WAKE_LOCK |
Allows the app to prevent the phone from going to sleep. |
WRITE_APN_SETTINGS |
Signature or privileged system permission. docs ↗ |
WRITE_SETTINGS |
Allows the app to modify the system's settings data. Malicious apps may corrupt your system's configuration. |
com.sec.android.RilServiceModeApp.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
- |
com.sec.android.app.factorymode.permission.KEYSTRING |
- |
com.sec.android.app.hiddenmenu.permission.KEYSTRING |
- |
com.sec.android.app.servicemodeapp.permission.KEYSTRING |
- |
com.sec.epdgtestapp.permission.SERVICE |
- |
com.sec.phone.permission.SEC_FACTORY_PHONE |
- |
samsung.permission.MPTCP_PERMISSION |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A057G | Android 15 | OEM Samsung | 1 | 8 Aug 2026 |
| Samsung | SM-A125F | Android 12 | OEM Samsung | 1 | 21 Jan 2026 |
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A515F | Android 13 | - | 1 | 30 Jun 2025 |
| Samsung | SM-A528B | Android 13 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 16 | OEM Samsung | 1 | 29 Jul 2026 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | OEM Samsung | 3 | 12 Sep 2026 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-F971B | Android 17 | OEM Samsung | 1 | 18 Sep 2026 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G766B | Android 16 | OEM Samsung | 1 | 5 Sep 2026 |
| Samsung | SM-G780F | Android 13 | OEM Samsung | 1 | 29 Dec 2025 |
| Samsung | SM-G973U | Android 12 | OEM Samsung | 2 | 10 Jun 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-M315F | Android 12 | - | 1 | 2 Feb 2026 |
| Samsung | SM-N950U1 | Android 9.0 | - | 1 | 20 Aug 2025 |
| Samsung | SM-N986B | Android 13 | - | 9 | 17 Jul 2025 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S731B | Android 16 | OEM Samsung | 1 | 11 Aug 2026 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S908U | Android 16 | OEM Samsung | 2 | 17 Sep 2026 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 17 Sep 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-S948U | Android 16 | - | 1 | 9 Sep 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-T976B | Android 13 | - | 1 | 21 Jul 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| Service mode RIL | en-gb | 24 |
| Service mode RIL | en | 20 |
| Service mode RIL | en-us | 19 |
| Service mode RIL | it-IT | 5 |
| Service mode RIL | nl-nl | 5 |
| Service mode RIL | de-de | 3 |
| Service mode RIL | en-nl | 3 |
| Service mode RIL | es-es | 2 |
| Service mode RIL | fr-fr | 2 |
| Service mode RIL | it-it | 2 |
| Service mode RIL | 2 | |
| Service mode RIL | es-ES | 2 |
| Service mode RIL | en-GB | 2 |
| Service mode RIL | es-us | 2 |
| Service mode RIL | ru-ru | 1 |
| Service mode RIL | cs-CZ | 1 |
| Service mode RIL | cs-cz | 1 |
| Service mode RIL | en-US | 1 |
| Service mode RIL | en-au | 1 |
| Service mode RIL | es-US | 1 |
| Service mode RIL | fr-FR | 1 |
| Service mode RIL | fr-dz | 1 |
| Service mode RIL | pl-PL | 1 |
| Service mode RIL | pl-pl | 1 |