Google ML Kit's barcode scanner adds the INTERNET permission and sends diagnostics, even in apps with no network code
While checking one of my own apps with Exodus Privacy, I noticed it had the INTERNET permission even though the code never touches the network. The culprit turned out to be Google ML Kit's barcode scanning library, which a very popular Flutter QR scanner uses under the hood. It adds INTERNET and ACCESS_NETWORK_STATE through a Google transport library, and sends diagnostic data to Google when the scanner is opened (device model, app version, an install-scoped ID, latencies, error codes). Google documents this, but you'd never guess it from an app that just reads a QR code.
A few things I took away from it:
- A "0 trackers" result on Exodus doesn't mean "no network". Check the permission list too.
- If an app that should be offline asks for INTERNET, a QR/barcode feature is worth suspecting.
- For developers: ZXing-based scanners decode entirely on-device and don't pull any of this in. You can confirm with the merged manifest or the manifest-merger report in your build folder.
Has anyone else run into libraries quietly adding network access like this? Curious which others are common offenders.