Skip to content → Skip to footer

Third-Party Screen Readers: Are They a Security Risk?

Unlike iOS, Android allows third-party apps to request accessibility permission, which makes it possible to develop screen readers for Android rather than limiting blind users to the built-in screen reader, TalkBack.

The presence of third-party screen readers has helped compensate for the lack of features and responsiveness issues in TalkBack. However, for a screen reader to work, it needs to be granted accessibility permission, which comes with powerful privileges that can pose serious risks if they fall into the wrong hands. The risks that come with granting accessibility permission, as well as the gains it provides, and the balance between security and openness, have been hot topics throughout the years. With the growing popularity of third-party screen readers, including new ones being developed recently with the help of AI-assisted vibe coding, the security aspect is becoming increasingly important to discuss and understand so that users can make informed decisions.

Before going any further, I want to state from the outset that the goal of this article is neither to give clearance to any screen reader or service, nor to accuse another of wrongdoing.

An Overview of the Accessibility Permission

The following definition is taken directly from the Android Developers website:

“An accessibility service is an app that enhances the user interface to assist users with disabilities or who might temporarily be unable to fully interact with a device. These services run in the background and communicate with the system to inspect screen content and interact with apps on the user’s behalf. Examples include screen readers (like TalkBack), Switch Access tools, and voice control systems.”

An article titled Accessibility Service – An Android Blessing and a Security Challenge in the Same Package from Bitdefender states:

“Android’s accessibility service is a powerful tool that allows people with disabilities to use mobile devices more easily. It’s also a favorite among criminals seeking to take over a device because it holds so much power.”

When granting an app permission to act as an accessibility service, the user gives the app access to powerful capabilities, including:

  • Reading Screen Content: The app can inspect the accessibility tree and read text exposed through it, which can include emails, text messages, account information, and other private data.
  • Tracking App Activity: The app can be notified when accessibility events occur, including changes in focus and interactions with different parts of the system.
  • Detecting UI Events: The app can receive information about events such as buttons being clicked, text fields receiving focus, checkboxes being ticked, and lists being scrolled.
  • Simulating User Input: The app can perform actions on the user’s behalf, including clicking buttons, scrolling through pages, and performing gestures such as swipes.
  • Inserting Text: The app can automatically type text into input fields.
  • Capturing Hardware Keys: An accessibility service can receive certain key events, depending on the device, Android version, and service configuration.
  • Performing Global Actions: The app can trigger system-wide actions such as pressing the Back button, going to the Home screen, opening notifications, and opening Quick Settings.

Although accessibility permission is built for services like screen readers, which are the focus of this article, it is also used by other apps to enable features that would not otherwise be possible. It is a core element of the popular automation app Tasker, and some launchers include an optional accessibility service to gain additional privileges.

Criminals and other bad actors have also found a great opportunity in accessibility services, which they try to seize and exploit to the fullest.

Google did not stay on the sidelines for long, taking active steps to make exploiting accessibility permission harder.

Since 2021, apps that use the AccessibilityService API have been required to provide additional information about their use of the API through Google Play’s accessibility declaration process before approval. Starting with Android 13, apps that are not installed from Google Play cannot simply be granted access to restricted settings, including accessibility access, by enabling the service from Accessibility settings. Instead, the user must first allow restricted settings for the app from its App info page and confirm the choice. Apps installed through some third-party installers can still bypass this step at the time of writing.

Google even restricts the use of unverified accessibility services when Advanced Protection is enabled, a mode intended for users who may face a higher security risk or who place a particularly high priority on privacy and security.

Installing and Using Third-Party Screen Readers on Android and the Security Threat

As stated above, granting any app the accessibility permission comes with a lot of privileges. However, in order for a screen reader to work, it must be granted accessibility permission. Without granting it this access, the screen reader is essentially useless, as its core functionality relies on the accessibility service it has.

Despite improvements, TalkBack on Android lacks many features that other screen readers provide. Many users find that third-party screen readers are more responsive compared to TalkBack, which still lags when performing certain tasks, such as scrolling, or on specific devices, especially those with mid-range or low-end processors. In fact, better responsiveness is an advantage that most developers of other screen readers use to advertise their apps.

No matter how we phrase it, granting any app accessibility service privileges poses a potential risk, even if the app is blocked from accessing the internet. However, this doesn’t mean that the app is really a risk, or that it is built with the intention to cause harm or steal users’ data.

If a Screen Reader Is Not in the Play Store, Does This Imply Foul Play?

The Play Store is the official app distribution store on Android. Apps are required to meet certain criteria to be hosted in the store. Additionally, Google performs security scans and checks to make sure that apps installed through the Play Store are safe. However, Google has its own set of rules that must be obeyed by developers who want their apps to be in the Play Store. If an app breaks any of those rules, it can be rejected from the store or have its approval revoked. Play Store rules are created to protect users, but there are restrictions that some apps cannot meet due to the features of the apps or how they work. There are app developers who decide willingly against submitting their apps to the Play Store, yet their apps can be completely safe, and the source code may be provided for anyone who wants to review it.

On the other hand, not having an app in the Play Store reduces the app’s reach, especially since it is always recommended to install apps from the Play Store as the safer choice for most users. People may also link the absence of a Play Store version to foul play, assuming that something prevents the app from gaining Google’s trust and being listed on the Play Store. As users should be more vigilant with accessibility services, it is understandable when a person refuses to install a screen reader that is not in the Play Store. However, not having a Play Store version does not directly translate to being a suspicious or risky app. There are apps that have functionalities that violate certain store restrictions, or simply apps whose developers don’t like to put their screen reader in the store. They could even opt for an open-source approach that is free from any store limitations, with both the updates and source code directly in the hands of users.

On the contrary, if a screen reader is on the Play Store, that doesn’t mean that it is completely risk-free, even if the risk is minimized. Bad actors are still able to sneak under Google’s verification mechanisms and land on the Play Store, with some apps gaining a high number of installs before being discovered. Additionally, accessibility services that are trusted by the Play Store could be doing shady things indirectly that affect users’ privacy.

It’s worth mentioning here that even if an app is sideloaded, when Play Protect is turned on, which it is by default, Play Protect scans the app for malicious software. If it identifies an app as potentially harmful, it can warn the user, disable or remove the app, or in some cases prevent it from being installed.

A Trick to Solve a Problem or Improve User Experience Is Not a Risk Even If It Breaks the Rules

In order for a screen reader to be effective, it should work reliably without crashes and should be free of restrictions. Some Android UIs trust TalkBack as the built-in screen reader, giving it certain privileges that are not given to third-party screen readers, even if they are granted accessibility permission. Apps might also provide accessibility UI changes or expose data to TalkBack only, not to third-party screen readers.

For this reason, some screen readers spoof TalkBack by running their service and showing it to the system and other apps as the TalkBack package. Such behavior is not necessarily wrongdoing, even though an app generally shouldn’t try to make other apps believe that it is a different app, if the purpose is simply to enhance usability rather than to gain access to data for suspicious reasons.

Another example is when an app is given the ability to turn on and off other accessibility services. While this is not a straightforward process because it requires issuing ADB commands, it is still doable with the right knowledge. An app with such capability poses a serious risk, and I cannot imagine that it would be considered compliant with Google’s rules. But if the app is built to assist users in toggling between their screen readers, we look at the matter differently.

An example is the Shortcut Menu app, which is available on GitHub as an open-source project, and which I highly doubt could be approved for the Play Store if its developer decided to add it there. The app is built to give users an accessible way to switch between screen readers or to turn on another screen reader if one stops working as intended.

The Difference Between a Screen Reader and the External Services It Uses for Some Functionalities

With the widespread use of AI, some screen readers allow the use of online AI services to describe content or perform OCR. They could also allow the use of non-AI services, such as translation or OCR. It is important to differentiate between the screen reader and the services it connects to. Third-party services are governed by the rules of the operators of those services, not by the screen reader utilizing them. This doesn’t mean that the screen reader is completely immune from responsibility. The screen reader should disclose the services it is connecting to, should encrypt data to ensure its safe transfer, should refrain from having any agreements with external services that allow user data to be misused, and should be transparent about everything it does regarding the data it sends.

Google TalkBack uses Gemini, which is also developed by Google, to describe and answer questions about content, but Google reassures users that the data is encrypted and deleted after the descriptions are received. Despite its bad reputation when it comes to user data, Google can be trusted with a matter like this one.

Unfortunately, this level of trust cannot be given to third-party screen readers. Jieshuo Screen Reader, for example, uses an online AI model from vivo to provide descriptions and answer user prompts, but there is no disclosure in the app itself of the exact model used or how the data is communicated. There is also no guarantee that the app would disclose if the AI service being used is changed.

As I am not a user of any other screen reader on the market, I cannot speak about how other screen readers deal with this subject. In all cases, using online services to analyse content should always be optional. If it is not, the user should at least be aware of the functionality that uses the external service so they can decide whether they want to use the screen reader or not.

Misusing a Screen Reader’s Advanced Capabilities Is Not the Fault of the Screen Reader

Here, the advanced extension system found in the Jieshuo Screen Reader comes to mind. It allows users to run Lua scripts, which could be used to communicate with Android APIs, upload and download data from the internet, add, edit, and delete files and folders, and more. Just because the Jieshuo Screen Reader enables the use of Lua extensions doesn’t mean that it is responsible for the damage inflicted by malicious extensions. Users should be vigilant enough to avoid running extensions without trusting their creators, especially since these extensions and tools could be encrypted, so their code cannot be reviewed by the user, even if they have the knowledge to do so, or at least by one of the popular AI services that can review Lua code.

Jieshuo Screen Reader might be the only popular screen reader that allows for advanced extensions on Android, but Windows screen readers have this capability as well. If I am a user of NVDA and I decide to run an untrusted add-on, putting myself at risk, I am responsible for the risks I am knowingly exposing myself to.

With that being said, it is not possible to avoid criticizing how the extension threat is handled by the Jieshuo developer. All users can upload extensions to the Jieshuo servers, where they are discoverable by all Jieshuo users who go to the Extensions, Tools, or Gesture Scheme additional resources. Those codes are not vetted or checked, although their presence on the Jieshuo service could suggest otherwise to an unsuspecting beginner or average user. This user might go ahead and download an extension or tool, trusting its legitimacy, only to fall victim to a malicious one. Jieshuo Screen Reader poses a risk to those users, even if indirectly, because there should be a review of uploaded extensions and tools, or at least a clear warning when downloading those codes that they are not monitored.

Human Error and Recklessness Are Part of the Story

They say that humans are the weakest link in cybersecurity, as many attacks are successful because of human error or reckless actions. With screen readers, the role of human error comes into play when installing unverified APKs. If you see a message on Telegram or WhatsApp that a new screen reader has been developed along with its APK, you don’t have to rush to install it. This could be malware waiting to take control of your device and data.

If you find someone posting about a new version of a screen reader you use, you don’t have to install and share this new version with others if you cannot trust the person who posted the APK. Popular screen readers have official places where they can be obtained. There are also reputable websites or channels that share official new versions when they are released.

Jieshuo Screen Reader, for example, is one of the screen readers that is widely shared in groups and channels, with modified versions sometimes being treated as official versions by users who think they are using the legitimate software when they are actually using a modified app. The screen reader has a GitHub page from which its releases can be downloaded, and new versions can also be downloaded through Jieshuo itself. There is also a website, although it is less known due to the lack of communication between the developer and the international user base.

Screen readers that are found on the Play Store are not immune either, as updates released through the Play Store can take more time to be approved and reach devices, and developers sometimes release versions as direct APKs before pushing them to the Play Store. When those APKs are modified and shared as the official versions, users may download them and put themselves at serious potential risk, something that could have been avoided simply by trying to find the official website or the screen reader developer’s channel.

Using Cracks Hands Over Your Device Control and Security Willingly to Bad Actors

Whenever an app hides some features behind a paywall, crackers try to use their skills to create and distribute pirated copies that allow users to access the Pro features without paying for them.

Putting aside the illegality and unethical nature of using cracked software, using a modified version of an app comes with the risk of malware being injected into it. This risk significantly increases when the app in question is an accessibility service like a screen reader.

The prominent example of a paid screen reader that is widely cracked is the Jieshuo Screen Reader, especially given the not-so-convenient method of purchase it utilizes. Maybe I won’t be exaggerating if I say that modified copies of Jieshuo are more widespread than official copies, with users sometimes even unable to differentiate between legitimate and modified copies. With so many cracked copies available, many users are put at risk of having their data stolen, as well as other damage that could result from running malware included in an accessibility service.

However, the screen reader’s developer cannot be held responsible for what a crack includes. In fact, the original developers are also victims, losing money due to unauthorized access to paid features, as well as suffering reputational damage because of the presence of cracked copies that could cause the original software to be flagged because of them.

Banking Apps and Third-Party Screen Readers

A screen reader can monitor your banking activity. It can go further by silently entering data and simulating clicks without you even knowing what is happening, especially since a screen reader can alter the speech you hear or even perform operations without providing any speech feedback at all.

Many banking apps treat third-party accessibility services as potential threats, with some of them blocking them indiscriminately and others only allowing services that come from the Play Store. Others might flag a specific screen reader and refuse to run even if the screen reader is only installed but not running. While the measures banks take to protect users from unauthorized access and transfers are understandable, deciding whether what a bank does is an indication of wrongdoing by a screen reader is a different matter. First, the user must know why the screen reader is denied access and whether this is a measure applied to all third-party screen readers, to those that don’t come from the Play Store, or to a specific screen reader. If users are able to get the necessary information from their banks, something I doubt many banks would provide, their assessment of the security of the screen readers they use would be more objective and not based on assumptions or fear.

In all cases, denying access to banking apps and their data undermines the use of a screen reader, even if the user trusts that screen reader completely. I personally don’t like very strict measures such as blocking access to an app just because another app is present on the phone, since making sure that no unverified accessibility service is running while the user is in the bank’s app should be enough, as the user is free to use a certain screen reader elsewhere.

Safety Is Not Guaranteed Only by Staying Away From Third-Party Screen Readers

Some users might be very cautious when it comes to running third-party screen readers, especially those that are not in the Play Store, yet they might have a more relaxed attitude toward other types of apps that deal with sensitive data. TTS engines are one important example. Some people don’t realize that TTS engines can be used as a weapon against them and their security. A TTS engine that suddenly appears in a group or channel is still capable of logging every single character sent to it from other apps, including the screen reader. This data can be uploaded to external services, where it is analysed in search of potentially valuable information. With AI tools that can analyse huge sets of data quickly, going through generated speech output is now an easy task.

If you use TalkBack but have a TTS engine that is constantly consuming an unjustified amount of data, you should be concerned about your security, as the feeling of safety you have may be false.

Another category of apps that is popular these days is online image description and text recognition apps. Those apps connect to an external service, typically an AI one, where the data is sent and analysed to provide the information requested by the user. The number of these apps is increasing quickly, assisted by vibe coding, which makes app development easier than ever. The same points raised about screen readers communicating with external services are valid here, but there is also the fact that some users don’t think about what they are sending to those services through apps that are not considered risky accessibility services.

The previous examples are for apps specifically designed for blind people, but other apps can be security threats without requiring accessibility service access. They pose a risk to both sighted and blind people. For this reason, it is always recommended to check the permissions an app asks for, as well as any suspicious behaviour or unjustified use of a permission, such as access to the microphone or camera, or unusually high data consumption.

People’s Attitudes Towards Third-Party Screen Readers

Opinions about the use of third-party screen readers differ within the blind community, with people at opposite ends of the spectrum.

On one hand, you find the highly cautious user who thinks that every third-party screen reader is a serious security risk, or even a spy agent harvesting every interaction, and should be avoided at any cost, with some applying this judgment only to screen readers that aren’t on the Play Store. While being reluctant to install potentially risky software is not a problem in itself, the issue starts when those people begin to make unsubstantiated claims. It is fine not to use a piece of software or not to like it, and to give your opinion about the risks of running an unverified accessibility service, but it is not fine to state your own thoughts as facts. Evaluating a software’s security can require procedures that include testing the software in a safe, sandboxed environment to analyse its behaviour and identify anything alarming.

On the other hand, you have the careless user who thinks that everything is safe. This is the user who doesn’t think for a minute before testing a screen reader, no matter where it comes from. This type of user is the one who argues that they don’t have anything to hide and that more cautious people are complicating the uncomplicated. Those users not only risk their own security and privacy, but they also risk the security and privacy of others, as we don’t live in a vacuum. We interact with other people through phones and tablets that could be running infected screen readers, and we connect to networks that could be subject to attacks. Those people increase the risk of data theft, impersonation to facilitate scamming others, and other forms of damage.

Human Bias and Judgments Play a Role in the Discussion

As with many other topics, our own subjective judgments play a role in whether we consider a screen reader secure and safe or not. Some people assume that a screen reader developed by someone from a certain country is a dangerous security threat, while one created by someone who resides in a country they trust is considered very safe. While it is true that some countries have better regulations and respect user rights more than others, criminal activities can be carried out anywhere. In fact, sometimes the reputation of a country’s strict laws can be a good cover for a bad actor to gain people’s trust. On the contrary, respect for users’ security and privacy can be found in the work of developers who might live in areas where the laws violate security and privacy. As they say, the person who knows the risk best is the person who has faced the risk.

Our biases are our own affairs that can affect what we trust and what we don’t trust, and it is a wise decision for someone who has escaped a totalitarian country not to use apps that come from developers in the country they ran away from. But we must present our statements as our subjective opinions, not as objective facts, if we are not willing or able to carry out the necessary evaluation procedures to determine what can be considered safe and what cannot.

After All the Rant, Are Third-Party Screen Readers Safe or a Horrible Nightmare?

I don’t have an answer to this question, nor is my goal to provide one. This article is an attempt to correct some misconceptions and raise awareness about accessibility services and what they can do. When you enable the accessibility service of a screen reader, you trust that screen reader, but at the same time, you agree that you are putting yourself under a theoretical risk. Those who follow my articles know that my primary screen reader of choice is Jieshuo, the notorious third-party screen reader. But many would not know that I remained reluctant to install this screen reader for years. Even now, I don’t have the confidence to tell people that this screen reader is completely innocent and safe, despite my personal opinion of it and my use of it.

I still have a tendency not to install new screen readers as soon as they are released, and I generally avoid screen readers that are neither on the Play Store nor open source. When it comes to open-source and closed-source screen readers, I lean toward an open-source screen reader free of Play Store limitations over a closed-source one found in the Play Store, provided I can identify its developers. Although I haven’t tested recent screen readers, I follow a few of them closely, with the possibility of installing them on my devices in the future. This doesn’t imply that I find the screen reader I use more secure than the screen readers I haven’t installed. In fact, the opposite could be true. Yet, I still stick to what I use because I have adapted my usage to the screen reader that I have used for years, without ignoring the possibility that something could go wrong one day.

Screen reader developers should be transparent about what data they collect, which external services they communicate with, and how they communicate with those services. When they offer advanced capabilities such as extensions,they should alert users to the risks of using unverified extensions instead of giving them a false sense of safety by letting them explore unvetted extensions or making it very easy to run extensions without any proper warning.

Whatever comes with the accessibility permission, restricting it is not the solution, as these restrictions cause more harm than they prevent. The solution lies in the hands of users, who should use common sense when they want to install a third-party accessibility service. Look at the gains versus the potential risks. Stay away from APKs from unknown sources, and don’t come near cracks. Keep Play Protect scanning for sideloaded apps enabled. Distinguish between the real risks of a screen reader and human error or recklessness. Look for any red flags, but don’t try to dictate your preferences as established facts.

About Author

Kareen Kiwan

Since her introduction to Android in late 2012, Kareen Kiwan has been a fan of the operating system, devoting some of her time to clear misconceptions about Android among blind people. She wrote articles about its accessibility and features on the Blindtec.net Arabic website, of which she was a member of its team. Kareen's experience was gained through her following of the Android-related communities and fueled by her love for technology and her desire to test new innovations. She enjoys writing Android-related articles and believes in the role of proper communication with both the blind screen reader Android users and app developers in building a more accessible and inclusive Android. Kareen is a member of the Blind Android Users podcast team and Accessible Android editorial staff.

Published in Articles

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Donate to Us

To uphold the standards of a robust and fully accessible project, we graciously request your support. Even a modest contribution can have a profound impact, enabling Accessible Android to continue its growth and development.

Donations can be made via PayPal.

For alternative methods, please do not hesitate to contact us.

We deeply appreciate your generosity and commitment to our cause.

Subscribe to Blind Android Users mailing list

RSS feed: Accessible Android on Mastodon Accessible Android on Mastodon

  • Untitled
    New app added to Accessible Android apps directory: Shortcut Menu accessible https://accessibleandroid.com/app/shortcut-menu/
  • Untitled
    New on Accessible Android: Accessibility RatingsYou can now rate apps in the Accessible Android Apps Directory from 1 to 5 based on accessibility.Add the screen reader and Android version you tested with, and optionally explain your rating with an accessibility note.Community ratings help others understand how accessible an app really is.Start rating the apps you […]
  • Untitled
    New app added to Accessible Android apps directory: Lexo Offline AI Voice Keyboard accessible https://accessibleandroid.com/app/lexo-offline-ai-voice-keyboard/
  • Untitled
    What’s New In Jieshuo 20261001 https://accessibleandroid.com/whats-new-in-jieshuo-20261001/