How Merged Manifest Permissions Sneak Into Your AAB
Gradle merges the manifests of every library you depend on into your final app manifest. This means a permission you never wrote yourself can end up in your release build because a dependency requested it — and Google Play's review sees the merged result, not your source.
A common surprise case: a maps or location library requests background location by default, even if your app only uses foreground location, silently expanding your permission footprint.
The fix
Fix: run ./gradlew :app:processReleaseManifest or view the merged manifest report in Android Studio before every release to see what actually shipped.
The same check runs automatically when you upload your bundle to the AAB analyzer — permissions, SDK fingerprints, and version info in one pass, free.
Keep going
Run this check on your own AAB
Free analysis, exports when you need them.
