Beacon Hub

Understanding the category

Security apps on phones and tablets

Why the same product does very different things on Android and on iOS, which advertised features are real on each, and which permissions deserve a second look.

Last reviewed: 16 September 2026 · part of the Beacon Hub 2026 edition

Quick answer. Mobile security apps are sold with one set of marketing across both platforms, but the platforms permit very different things. On Android an app can genuinely scan and intervene. On iOS it cannot scan the device at all, and what it actually provides is web filtering, VPN and breach alerting. Judging a mobile subscription means knowing which of the two you are buying for.

Two platforms, two different questions

A phone holds more sensitive material than most household computers: banking applications, messages, photographs, the email account that can reset every other password, and the authentication app guarding all of it. The instinct to protect it is sound. What confuses people is that the protection available depends less on which product they choose than on which platform they are on.

Android permits applications relatively broad access, within a permission system the user controls. Third-party security software can therefore do recognisably the same job it does on a desktop. iOS restricts applications to their own sandbox and provides no mechanism for one app to inspect another or scan storage. This is a deliberate architectural decision, and it means an identical product name delivers substantially different capabilities on the two platforms.

What an app can do on Android

Android applications are isolated from each other but can request permissions for shared resources, and the platform provides interfaces that security software can legitimately use. In practice a third-party app on Android can scan installed applications and files it has access to, check applications as they are installed, filter web addresses through a local VPN profile, and warn about permissions that look excessive for what an app claims to do.

What it adds over what is already there is the question worth asking. Google Play Protect is on by default on certified Android devices and scans applications from the Play Store and elsewhere on the device. A third-party product is therefore an addition rather than a replacement, and the honest case for it rests on the extras: filtering that applies outside the browser, coverage managed alongside the household's other devices, and support.

What an app can do on iOS

Less than the category name implies, and this is worth being blunt about because it is the single most misleading thing in mobile security marketing. On iOS, applications are reviewed before distribution, run sandboxed, and cannot read other applications' data or the wider file system. No application can therefore scan an iPhone or iPad for malware. Any product implying it performs such a scan is describing something the platform does not allow.

The functions that are real on iOS are worth having in their own right. A content or web filter, implemented through a VPN profile or a content-blocker extension, can stop known fraudulent sites loading. A VPN can encrypt traffic on a network you do not control. Breach monitoring can tell you an account of yours appeared in published breach data. Those are genuine features. They are simply not scanning, and a subscription bought for scanning on iOS is a subscription bought on a misunderstanding.

The tell

If an iOS product's description animates a scan, shows a progress bar over your "device storage", or reports a threat count for your phone, treat the whole description sceptically. The platform does not expose the information such a display would require.

Which advertised features are real on which platform

Commonly advertised mobile security functions, by platform
Advertised functionAndroidiOS and iPadOS
Malware scanning of the devicePossible; duplicates Play Protect to a degreeNot possible — the platform provides no access
Checking apps as they installPossibleNot applicable; apps come through Apple's review
Web and phishing filteringPossible, usually via a local VPN profilePossible, via a VPN profile or content blocker
VPNYesYes
Breach and identity alertsYes — a service, not a device functionYes — a service, not a device function
Blocking other applicationsPossible with elevated permissionsNot possible for third-party apps
Finding a lost deviceBuilt into the platform alreadyBuilt into the platform already

Capabilities described are platform-level, not product-level. What any particular subscription includes on your phone is stated by that vendor, and should be read on the vendor's own page before purchase.

Permissions, and which ones matter

Mobile security apps ask for unusually broad permissions, and the request is often legitimate: filtering traffic requires a VPN profile, and blocking apps requires elevated access. The difficulty is that these are precisely the permissions malicious software wants, which is why where you obtained the app matters more than what it promises.

Accessibility services (Android)
Allows an app to observe screen content and act on your behalf. Essential for genuine accessibility tools; also the most abused permission on the platform. Review what holds it, and remove anything you do not recognise.
Device administrator (Android)
Grants control over device-level functions such as locking and wiping. Legitimate for anti-theft features, and worth removing when an app is uninstalled.
VPN profile (both platforms)
Routes traffic through the app. Necessary for filtering, and it means the provider can see the traffic. Grant it only where you accept that, and read what the provider says it logs.
Notification access
Lets an app read incoming notifications, including message contents and one-time codes. Rarely necessary for security software, and a serious exposure if granted to the wrong app.

What actually goes wrong on phones in Australia

Text messages impersonating a delivery company, a toll operator or a bank remain among the most commonly reported approaches, and they do not involve malware at all — they involve a convincing page asking you to log in. Scamwatch publishes current examples at scamwatch.gov.au, and the Australian Cyber Security Centre's guidance for individuals is at cyber.gov.au.

Against that pattern, the useful protections are a filter that blocks the destination, multi-factor authentication so a captured password is not sufficient on its own, and the habit of opening the organisation's own app instead of following a link. Note that only one of those three is something a subscription sells you.

The other common problem is not malware either. It is someone with access to the phone installing monitoring software on it. The eSafety Commissioner publishes guidance on this and on where to get help, and it is a situation where a security app's app-listing feature can genuinely be useful on Android.

Before you install anything

  • Check what the platform already does. Play Protect on Android; on iOS, updates and the App Store review model.
  • Read which functions the vendor states are available on your platform, not the combined feature list.
  • Install only from the official store for your device, and check the developer name matches the company you meant.
  • Review the permissions requested against the functions you actually want. Decline the rest.
  • Check the licence covers the number of devices in your household, and find the renewal price before you subscribe.

If a mobile subscription is the route you have decided on, TotalAV is the product Beacon Hub has a commercial arrangement with, and it publishes applications for mobile platforms. What it includes on Android and on iOS is stated by the vendor, and those statements — not this page — are what you should base the purchase on.

Paid link: if you subscribe after following it, Beacon Hub receives a commission from the merchant. It costs you nothing extra and the price is set by the vendor, not by us. Check the platform-specific feature list and the renewal terms on the vendor's own site.

Visit the TotalAV website

Common questions

Can a security app scan an iPhone for viruses?

No. iOS prevents any application from reading other applications' data or scanning device storage, so no app can perform a malware scan on an iPhone or iPad. Apps on iOS deliver other functions instead, such as web filtering, a VPN or breach alerts, which operate within the platform's rules.

Is a security app worth installing on Android?

It depends on how the phone is used. Google Play Protect already scans applications by default. An additional app adds value mainly for people who install software from outside the Play Store, share the device with children, or want web filtering that applies beyond the browser.

Why do mobile security apps ask for so many permissions?

Because the functions they advertise require them: web filtering usually needs a local VPN profile to inspect traffic, and app-blocking features need device administrator or accessibility access. Those are legitimate for that purpose, and they are also exactly the permissions malicious apps request, so grant them only to software you obtained deliberately from an official store.

Does a VPN in a security bundle make a phone anonymous?

No. A VPN encrypts traffic between the device and the provider's server and hides your address from the sites you visit. It moves trust to the VPN operator rather than removing it, does not stop malware, and does not make you anonymous.