Mobile device collects an amount of sensitive data should be protected and controlled. Each OS provides extensive APIs that are controlled by a permission system as part of OS. This paper proposes an investigation of ‘prebuilt’ over privileged capabilities due to insufficient documentation on security.