India Proposes Mandatory Source Code Sharing for Smartphones, Drawing Pushback from Apple and Samsung
A sweeping new regulatory draft in India would require smartphone manufacturers to submit their operating system source code to government labs for security review. The proposal has sparked intense resistance from major tech companies over intellectual property and privacy concerns.
By Naina Verma
- Global Device Manufacturers
- Maintains that mandatory source code sharing compromises intellectual property and introduces severe security vulnerabilities.
- Indian Regulatory Authorities
- Argues that deep access to device software is necessary to protect consumers and national infrastructure from rising cyber threats.
- Cybersecurity Analysts
- Warns that requiring government approval for security patches will delay critical updates and leave users exposed to zero-day exploits.
Why it matters
If implemented, these regulations would force global tech giants to choose between compromising their core security architecture or exiting the world's second-largest smartphone market. The mandate could also set a global precedent, encouraging other nations to demand similar access and fracturing the unified security models that currently protect consumer devices.
India has drafted a sweeping set of security regulations that would force smartphone manufacturers to hand over their operating system source code to government-designated testing labs. The proposal, part of a broader 83-point security framework, has triggered intense, behind-the-scenes resistance from Apple, Samsung, and other major device makers who view the mandate as an unprecedented risk to their intellectual property and global security architecture.[1][2]
The draft framework, known as the Indian Telecom Security Assurance Requirements (ITSAR), is positioned by the government as a necessary defense against rising online fraud in a market of nearly 750 million smartphone users. Under the proposed rules, manufacturers would have to submit their source code—the foundational instructions that dictate how iOS and Android operate—for "vulnerability analysis" and "source code review."[2][3]
While the government frames this as a consumer protection measure, the reality of implementation tells a different story. Handing over proprietary source code to third-party labs expands the attack surface, creating new potential leak points for trade secrets and zero-day vulnerabilities. The industry consortium MAIT, representing Apple, Samsung, Google, and Xiaomi, explicitly told the government that compliance is "not possible" due to secrecy and privacy constraints.[1][4][5]
Beyond the source code handover, the ITSAR draft includes a requirement that could fundamentally alter how devices are maintained. Manufacturers would be forced to notify the National Centre for Communication Security about major software updates and security patches before releasing them to users, giving the agency the right to test them first.[1][4]
Beyond the source code handover, the ITSAR draft includes a requirement that could fundamentally alter how devices are maintained.
This creates a glaring paradox: a policy marketed as enhancing security would actively delay the deployment of critical, time-sensitive patches. If a zero-day vulnerability is actively being exploited, waiting for a government lab to approve the patch leaves millions of users exposed during the bureaucratic review process.[3][4]
The 83-point framework doesn't stop at code review. It also mandates that devices perform automatic, periodic malware scanning—a process that manufacturers warn would significantly drain battery life. Furthermore, the rules would require phones to store digital logs of system activity locally for at least 12 months, a demand that companies argue exceeds the storage capacity of many entry-level devices.[1][5]
Not all of the proposed changes are hostile to users. The framework includes mandates that would allow consumers to completely uninstall pre-loaded applications—often referred to as bloatware—and block apps from accessing cameras and microphones in the background. These specific provisions align with broader global trends toward user empowerment, even as the source code demands diverge sharply from international norms.[1][4]
The pushback highlights the global stakes of localized tech regulation. There is currently no precedent in North America, Europe, or Australia for mandating source code disclosure as a baseline regulatory requirement for consumer electronics. While India's IT ministry has publicly stated that consultations are ongoing and denied that the source code mandate is finalized, the existence of the draft has forced the industry to draw a hard line. If implemented, the framework could fracture the global smartphone ecosystem, forcing companies to choose between compromising their core security architecture or exiting the world's second-largest market.[2][3][5]
What to know
- India has drafted an 83-point security framework that would require smartphone makers to share their operating system source code with government labs.
- The proposal mandates that companies notify authorities and seek approval before releasing major software updates and security patches.
- Industry consortium MAIT, representing Apple and Samsung, has strongly opposed the rules, citing severe risks to intellectual property and user privacy.
- Additional requirements include mandatory local storage of system logs for 12 months and built-in, periodic malware scanning.
- The government has publicly denied that the source code mandate is finalized, though confidential drafts indicate it remains under active consideration.
Where opinion splits
The Regulatory Stance
India's push for sovereign oversight of digital infrastructure.
Indian authorities frame the ITSAR draft as a necessary evolution of national security in an era of rampant data breaches. With nearly 750 million smartphone users, the government argues that relying entirely on the opaque security assurances of foreign corporations is no longer sufficient. By demanding the ability to independently verify source code and test security patches in state-designated labs, regulators aim to ensure that devices operating within their borders do not contain hidden backdoors or unpatched vulnerabilities that could compromise national infrastructure.
The Manufacturers' Dilemma
The existential risk to intellectual property and global security models.
For Apple, Samsung, and Google, the proposal represents a red line that threatens their entire operational model. Source code is the foundational intellectual property of these companies; distributing it to third-party testing facilities exponentially increases the risk of leaks and corporate espionage. Furthermore, manufacturers argue that the mandate to pre-clear security updates with a government agency fundamentally breaks the modern cybersecurity paradigm. In a landscape where zero-day vulnerabilities must be patched globally within hours, a bureaucratic approval bottleneck could leave millions of devices defenseless while regulators review the code.
Sources
[1]The Economic TimesIndian Regulatory AuthoritiesIndia proposes requiring smartphone makers to share source code with the government
Read on The Economic Times →
[2]International Business TimesGlobal Device ManufacturersGlobal smartphone manufacturers are pushing back against a sweeping set of proposed security rules in India
Read on International Business Times →
[3]CybernewsCybersecurity AnalystsA reported proposal to tighten smartphone security standards in India has put the spotlight on an unusual demand
Read on Cybernews →
[4]Gadget HacksCybersecurity AnalystsIndia Demands Source Code: Apple, Samsung Push Back Hard
Read on Gadget Hacks →
[5]CGTNIndian Regulatory AuthoritiesIndia proposes requiring smartphone makers to share source code with the government
Read on CGTN →
[6]The StreetGlobal Device ManufacturersIndia's proposed rules put Apple, Google, and Samsung in a compliance bind
Read on The Street →
Comments
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.


