Mumbai: India’s smartphone security policy has come under renewed scrutiny following recent media reports suggesting that the government may ask smartphone manufacturers to share their source code as part of a broader cybersecurity overhaul. The reports claimed that authorities were considering the move to curb rising cyber fraud and mobile-based financial crimes in India, which has one of the world’s largest smartphone user bases.
According to the reports, the proposed measures could require phone makers to disclose operating system changes and submit software updates for review. The claims triggered concern among global smartphone brands, which warned that such steps could affect intellectual property protection and global security standards.
Government clarification on source code claims
Soon after the reports surfaced, the government moved to clarify its position. The Press Information Bureau (PIB) issued a fact check stating that claims about forcing smartphone manufacturers to share their source code were false. No such proposal had been finalised or approved yet, according to officials.
The Ministry of Electronics and Information Technology (Meity) explained that discussions with smartphone makers were part of routine consultations. These consultations aim to explore ways to strengthen mobile security and protect users from cyber fraud. Stakeholder feedback is a normal part of policy formulation and should not be confused with regulatory mandates, according to the ministry.
Why app permissions are a growing security concern
One of the key issues linked to India’s smartphone security policy is the way mobile applications seek permissions. Many apps request access to cameras and microphones even when their core functions do not require it. For users, this often raises questions about necessity and safety.
Developers usually request such permissions for analytics, advertising tools, or future feature expansion. In many cases, third-party software libraries embedded within apps also demand access to device hardware. While most apps do not misuse these permissions, excessive access increases the overall attack surface of a smartphone.
How excessive access increases cyber risk
Cybersecurity experts warn that over-permissioned apps can become attractive targets for attackers. If a vulnerable or compromised app gains access to a camera or microphone, it could expose sensitive user information. Attackers can exploit even limited access to smartphones through malware, phishing campaigns, or spyware
Although modern mobile operating systems include safeguards, the presence of unnecessary permissions still creates risk. As digital payments, online banking, and identity-based services grow in India, smartphones have become critical targets for cybercriminals. This makes permission control a central issue in any discussion on mobile security reform.
Policy communication and industry concerns
The confusion around the source code reports also highlights challenges in policy communication. Probably, people can misinterpret early-stage consultations as final decisions, triggering public anxiety and market speculation. Government officials have reiterated that any changes to India’s smartphone security policy will follow due process and industry engagement.
Smartphone makers, on their part, have consistently argued that security should focus on outcomes rather than intrusive controls. They maintain that protecting user privacy, ensuring timely updates, and preventing malware are better achieved through collaboration rather than mandatory disclosures.
TechHerald.in contacted mobile brands, including Samsung and Oppo, for comment on the story, but none had responded by the time of publication.
Balancing user safety and innovation
The debate reflects a broader challenge for policymakers. India needs stronger safeguards against cyber fraud, but it must also preserve innovation and trust in the smartphone ecosystem. With millions of users relying on mobile devices for daily transactions, security failures can have wide social and economic impact.
As discussions continue, clarity around app permissions, software transparency, and responsibility sharing will be crucial. India’s smartphone security policy is still evolving, but its direction will shape how users, companies, and regulators address cybersecurity risks in the years ahead.
