Here’s a bold statement: pre-installed apps that have deep system permissions are the single most underestimated privacy risk in consumer smartphones today. The uproar over Samsung’s AppCloud is proving exactly why.

kets for years. Marketed as a recommendation engine for third-party apps, it was originally developed by ironSource, an Israeli-founded company now owned by US-based Unity. The controversy erupted after Beirut-based digital rights group SMEX published an open letter urging Samsung to “end forced Israeli-founded bloatware installations,” citing “serious privacy and security risks” citing “serious privacy and security risks” and the inability for users to opt out.
Technically, AppCloud is a system app. That lofty status comes with privileged access to the core functions of Android, bypassing restrictions set on ordinary apps found in the Play Store. According to analysis by SMEX, it is “deeply integrated into the devices’ operating system,” such that removal requires root access a process that voids warranties and further exposes devices to vulnerabilities. Even disabling it through Settings isn’t permanent; system updates can silently re-enable it.
Though Samsung’s official statement to KnowYourMobile.com emphasizes compliance with local laws and providing “the highest level of protection possible,” it does not say if users will ever be able to completely delete AppCloud. The app is subject to the company’s privacy policy, and users can disable the app themselves, but the general lack of transparency about what data is collected remains a sticking point.
SMEX claims AppCloud collects sensitive biometric data, IP addresses, location information, and device fingerprints without explicit consent. This is in line with the broader research of pre-installed apps on budget Android devices, which estimates that about 9% leak sensitive personal data such as IMSI, IMEI, and precise GPS coordinates. Many also declare the INSTALL_PACKAGES permission, which is supposed to enable silent installation of other apps, a capability AppCloud reportedly possesses.
Historically, ironSource has drawn fire for its “InstallCore” platform, which bundled software without clear user permission and bypassed security warnings, earning classification as a “potentially unwanted program” from anti-malware tools. While there is no confirmed evidence that AppCloud engages in similar behavior today, the optics of shipping an unremovable app from a company with that track record are undeniably problematic particularly in West Asia and North Africa, where Israeli-linked technology faces legal and political barriers.
The problem, from an engineering standpoint, is the way in which system apps have been treated by Android’s architecture. They sit in the system partition, which is read-only, and even then protected by the OS through signature verification. Removing them requires some kind of cooperation with the OEM and unlocking the bootloader to reflash firmware, operations that are inaccessible to most users and trigger security flags like Samsung’s Knox warranty bit. It’s possible for advanced users to attach their device to a PC and remove system packages for the active user profile using ADB commands, but this does not remove the app from the system image and may not persist across major updates.
Security researchers have warned that pre-installed apps represent a supply chain attack surface. As Google noted in its own Android Security review, an attacker needs only to compromise one participant in the OEM’s partner network to push malicious code to millions of devices. Because system apps often embed third-party libraries from ad networks or analytics providers, they can leak data to multiple external entities without user awareness.
In the case of AppCloud, its integration with ironSource’s Aura technology-designed to “optimize device experiences” by surfacing apps and content-raises further questions about how recommendation algorithms interact with user data. Without a public privacy policy specific to AppCloud, consumers cannot verify whether their information is anonymized, aggregated, or shared with outside partners.
The backlash is amplified by regional sensitivities and the viral spread of posts labeling AppCloud “unremovable Israeli spyware.” While the spyware claim remains unsubstantiated, the underlying technical reality-a persistent, privileged app with opaque data practices-is enough to fuel demands for change. Privacy advocates are calling for Samsung to provide a clear opt-out during device setup, publish a full data usage disclosure, and halt preloading in sensitive markets.
For the time being, only one method of removal is certain, and it’s one most users will never try: rooting the device and flashing a new system image. Until the OEMs decide to make deletion an option, AppCloud serves as a case study in how bloatware can go from an annoyance to a legitimate security concern.

