Updated 28 August 2026 · Cornerstone guide
Bug detector app: can a phone find a listening device?
Audio bugs are the hardest of the three surveillance categories to find, and the one where app store marketing is furthest from the physics. Here is what a phone can honestly do, what it cannot, and the sweep that finds more than any app.
Quick answer. A phone cannot sweep radio frequencies, so it cannot find a transmitting audio bug the way a hardware sweeper can. It cannot hear an ultrasonic carrier, it cannot see through a wall, and it certainly cannot find a voice recorder, because a recorder emits nothing at all. What a phone genuinely does is narrower and more useful than the marketing suggests: it can audit itself for monitoring software, list devices on the local network, help you inspect suspicious objects at contact range with the magnetometer, and guide a physical search. In practice the most common real bug in 2026 is not a device hidden in a lamp. It is software running on a phone that somebody else set up.
Disclosure: Appsera is building a detection app for iPhone, so we have a commercial interest in this topic. That is why this page leads with what a phone cannot do. Every capability claim below names the sensor, the API or the study behind it, and where a technique does not work we say so rather than selling around it.
Contents
- The five things people mean by “bug”
- Why an RF signal detector app cannot exist
- What a phone genuinely does, sensor by sensor
- The bug that is actually on your phone
- Smart speakers, TVs and the legitimate microphones
- The physical sweep of a room
- Hardware bug sweepers and what the evidence says
- When this stops being a DIY problem
- You found something. Stop and read this
- What we are building
- Frequently asked questions
The five things people mean by “bug”
Most advice on this subject is useless because it treats a listening device as one thing. It is five things, they leak in completely different ways, and a method that finds one is worthless against the others. Work out which one you are actually worried about and everything below gets simpler.
| Type | What it does | What it emits | Findable by a phone? |
|---|---|---|---|
| 1. RF transmitter The classic bug |
Microphone plus a small radio transmitter. Sends audio continuously to a receiver somewhere nearby. | A continuous or bursty radio carrier, often in the 300 to 900 MHz range or on Wi-Fi bands. | No. A phone has no wideband receiver. |
| 2. GSM or LTE bug The SIM card bug |
A microphone with a mobile radio. Calls out, or answers a call silently, so range is unlimited. | Short cellular uplink bursts, silent in between. | No, and even real test equipment has to be within about a metre during a burst. |
| 3. Voice recorder Passive |
Records to internal memory. Somebody must come back and collect it. | Nothing. No radio energy of any kind. | No. Nothing to detect, on any equipment. |
| 4. Monitoring software Stalkerware |
An app or profile on a phone or laptop that streams the microphone, messages and location. | Ordinary encrypted network traffic, indistinguishable from normal use. | Yes, and this is the one category where the phone is the right tool. |
| 5. A legitimate microphone Smart speaker, TV, laptop, baby monitor |
Does what it was sold to do, for whoever controls the account. | Normal network traffic. | Yes, by auditing the account and the network rather than by scanning. |
Two conclusions fall straight out of that table, and they are the opposite of what the category sells. The three device types a “bug detector” app claims to find are exactly the three a phone cannot find. And the two that a phone can genuinely help with are the two that most people never check, because they involve looking at settings rather than waving a handset around a room.
Why an RF signal detector app cannot exist
Search the app stores for “rf signal detector” and you will find dozens of apps with animated spectrum displays and sweeping needles. None of them is reading radio frequency energy, because no phone can. This is worth understanding properly, because once you understand it you can never be sold one of these apps again.
What a real RF detector is
A hardware bug sweeper is a broadband power meter. A wide antenna feeds a diode detector that measures total radio energy across a huge span of frequencies at once, with no ability to tell one signal from another. That crudeness is the point: it does not care what protocol a bug speaks, only that the bug is radiating.
Why a phone is built to do the exact opposite
Every radio in a phone, cellular, Wi-Fi, Bluetooth, GPS, NFC and ultra-wideband, sits behind its own antenna and its own filter whose entire job is to throw away everything outside its assigned band. That filtering happens in the analogue front end, before any software could see the signal. The energy from a 433 MHz bug never reaches the receiver. It is removed by a passive component, and no software update can undo a component.
On top of that, the basebands are closed systems that demodulate only their own protocol and expose only decoded results. Neither iOS nor Android has any API that returns raw wideband signal strength. On iOS the restriction is documented: Apple’s technote TN3111 states that “iOS does not have a general-purpose API for Wi-Fi scanning and configuration”, and that is for Wi-Fi, a band the phone actually has a radio for.
So what is the animation showing you? One of three things. Wi-Fi, Bluetooth or cellular signal strength values, relabelled as RF. The magnetometer, which is a magnetic sensor and not a radio at all. Or nothing, a generated waveform with a needle that moves because movement looks like measurement. We have seen all three. An app cannot detect an analogue room transmitter, a GSM bug between bursts, or a 433 MHz link, and that includes any app we will ever ship.
What the real detection of a cellular bug looks like
There is now a published method for finding cellular devices, and its details are the clearest possible illustration of the gap. At USENIX VehicleSec in 2025, a team from NYU Tandon tested five consumer LTE trackers, which use the same radio approach as a GSM bug. Four of the five transmitted at one minute intervals and the fifth at five minute intervals, and were completely silent in between. Detection was done on the LTE uplink at frequencies such as 709 MHz and 1877.5 MHz, using a tinySA Ultra spectrum analyser costing around $150, and reliable range was three feet or less.
So even with a real instrument and a peer-reviewed method, you have to be within a metre of the device and present during the one second per minute it is talking. A phone cannot perform any step of that. This is not a software gap that a clever developer will close.
What a phone genuinely does, sensor by sensor
Detection claims are only credible when you can name the sensor doing the work. Here is the honest inventory for audio surveillance.
Network enumeration: real, and bounded
If a device is on the same network you are on, and it responds to discovery, and its MAC address vendor prefix is registered to a manufacturer you can look up, you can see it. That is three conditions, any one of which can fail. A bug on LTE is not on your network. A device on a hidden SSID or on a separate guest network is not on your network. A recorder is on no network at all. And on iOS the enumeration you can perform is narrower than on Android because of the platform restrictions above.
The correct way to read this tool: a hit is strong evidence, a miss is no evidence. Any app that turns an empty network scan into a green “your room is clear” badge is lying to you with true data.
The magnetometer: real, but only at contact range
A phone’s compass is a three-axis magnetic sensor, and a common part resolves roughly 0.15 microtesla per step. That is sensitive. The problem is not sensitivity, it is geometry: magnetic field strength falls with the cube of distance. Double the distance and the field drops by a factor of eight. A magnet that reads clearly with the phone touching it is below the noise floor a metre away.
So the honest description is a contact-proximity metal and magnet finder. It is useful for asking “is this smoke detector stuck to a magnet plate that should not be there”, and useless for sweeping a room. Steel studs, door frames, hinges, radiators, speaker magnets and the phone’s own magnetic case all read as anomalies. Take the case off before you start.
The camera: useful for cameras, not for microphones
Lens retroreflection and near-infrared viewing are genuine techniques with measured results, and they find cameras. A microphone has no lens to reflect light and no illuminator to glow. If you are searching for a device that might do both, the camera techniques are worth running, and we cover them properly in the hidden camera detector guide. For a pure audio bug they contribute nothing.
The microphone: no, and be sceptical of anyone who says otherwise
Some apps suggest listening for ultrasonic beacons or for the noise a bug supposedly makes. Two problems. A phone microphone’s anti-aliasing filter and sample rate cut off shortly above the audible band, so genuine ultrasound is largely inaccessible. And an audio bug is designed to be acoustically silent, because a bug that makes a noise is a bug that gets found. We found no research supporting any acoustic method of locating a listening device, and would treat any app claiming one as unsupported.
What is left
Stated plainly: a phone contributes a network view, a contact-range magnetic probe, camera techniques that only apply to cameras, a self-audit of its own software, and a structured search checklist. That is a real toolkit. It is not a scanner, and the honest version of this category is a search assistant rather than a detector.
The bug that is actually on your phone
If somebody is listening to you in 2026, the odds strongly favour software over hardware. Monitoring apps are cheap, need no physical hiding place, survive a room sweep untouched, and give the person far more than audio. They are also the one category a phone can genuinely audit, which is why this section is the most useful on the page even though it has nothing to do with detectors.
On iPhone
- Check for a configuration profile. Settings, General, VPN & Device Management. A personal iPhone should normally have nothing here, or only a profile from your employer that you know about. A profile you do not recognise can grant broad control over the device.
- Check Screen Time. Settings, Screen Time. If it is on with a passcode you did not set, another person may be receiving activity reports.
- Check who is in Family Sharing and what is shared with them, and check Find My, People, for anyone sharing your location.
- Check the microphone indicator. An orange dot appears in the status bar whenever any app is using the microphone, green for the camera. Watch it while you are not using anything. Pull down Control Centre to see which app it was.
- Review Settings, Privacy & Security, Microphone and revoke every app that has no business listening.
- Check Apple ID devices. Settings, your name, and look at the device list. A device you do not recognise means somebody has your account, which is a bigger problem than any bug in a lamp.
On Android
- Settings, Security, Device admin apps. Anything unfamiliar with device admin rights is a serious finding.
- Settings, Apps, Special app access, then Usage access and Display over other apps. Monitoring tools need these and they are visible.
- Check the privacy dashboard for recent microphone use, and revoke microphone permission from anything unexpected.
- Google Play Protect scan, then check your Google account’s device list at the security page.
- Note that some monitoring tools hide their launcher icon. The permission screens above are more reliable than scrolling the app drawer.
Signs that are worth noticing and are not proof
Battery draining faster than it used to, the phone warm when idle, a jump in background data, the device slow to shut down. All four have ordinary explanations far more often than sinister ones. Treat them as a reason to run the checks above, never as a conclusion.
Before you remove anything, read this. If you think the person monitoring you is someone you live with or know, removing the software tells them you found it. The Coalition Against Stalkerware’s guidance for survivors is explicit that removing monitoring may be detected by the abuser and could increase the abuse, and that you should only attempt removal if you believe it is safe to do so.
Do the checking on a device the other person has never had access to, if you possibly can. A library computer or a friend’s phone is safer than the device in question. Then talk to an advocate before you change a setting. In the United States, the National Domestic Violence Hotline is available around the clock on 1-800-799-7233, or text START to 88788. In the United Kingdom, the National Domestic Abuse Helpline is 0808 2000 247 and the National Stalking Helpline is 0808 802 0300. Across the European Union, 116 006 reaches victim support. techsafety.org, refugetechsafety.org and stopstalkerware.org all publish guidance written for exactly this situation.
Smart speakers, TVs and the legitimate microphones
Before you conclude that someone planted a device, count the microphones that are already in the room with your permission. A smart speaker, a smart TV, a games console, a video doorbell, a baby monitor, a laptop, a tablet, a smart watch and every phone in the house. None of them is a bug. Each of them is a microphone attached to an account, and the question that matters is who controls the account.
- Review who has access to each account. A shared household account means shared voice history.
- Check the voice history in the assistant’s app and see what was actually captured. Both major assistants let you review and delete recordings.
- Check the camera and microphone mute switches on speakers and displays. On many devices the mute is a hardware disconnect rather than a software flag.
- Check the baby monitor. Older units transmit unencrypted analogue audio that anything on the same frequency can receive, which makes the monitor you installed yourself the most likely unintentional bug in most homes.
This is unglamorous and it is where the real answer usually is. A room sweep that ignores the four devices already listening on purpose is theatre.
The physical sweep of a room
If you have reason to believe a physical device is present, a careful manual search finds more than any consumer tool. The relevant number here comes from the 2021 LAPD study presented at ACM SenSys, which measured hidden camera detection across 379 participants: a naked eye search found 46.0% of devices, while the widely sold K18 hardware detector managed 62.3% with a 26.9% false positive rate. The study was about cameras, so the rates do not transfer directly to audio bugs, but the shape of the finding does. Careful looking is roughly in the same league as a cheap detector, and it costs nothing.
Before you start
- Take your phone out of any magnetic case if you intend to use the magnetometer.
- Get a torch and a small mirror. Work in daylight if you can.
- Search when you will not be interrupted, and if the situation involves a person you live with, read the safety guidance above first.
Zone 1: anything with permanent mains power
A bug that runs on a battery has to be serviced. A bug that runs on mains does not, which is why the highest-value hiding places all have a permanent power supply. Check power strips, USB chargers and adapters left plugged in, mains extension blocks, lamps and lamp bases, clock radios, smoke and heat detectors, air purifiers, wall sockets with an unfamiliar faceplate, and light switches.
Zone 2: the objects nobody moves
Bookshelf ornaments, picture frames, wall clocks, plants and their pots, tissue boxes, air fresheners, soft toys, curtain rails and pelmets, the top of a wardrobe. The common factor is that they are never touched, so a device placed there is safe for months.
Zone 3: furniture and the underside of things
Under desks and tables, under drawers and behind them, in sofa seams and under cushions, in mattress edges and bed frames, behind headboards. Run a hand where you would never normally look.
Zone 4: gifts and recent arrivals
An object that appeared recently and that you did not choose deserves particular attention, especially if it plugs in. This is the single most reliable pattern in real cases: the device is inside something that was given to the person or installed for them.
Zone 5: infrastructure
Ceiling and air vents, junction boxes, the space above suspended ceiling tiles, telephone sockets and the router itself. Look for wiring that does not belong, and for screws with fresh tool marks on old fittings.
What you are looking for. Most consumer audio devices are between the size of a coin and a matchbox, and the giveaway is usually context rather than appearance: a device in a place with no reason to have one, a wire going somewhere it should not, a fitting that does not match the others in the room, or dust disturbed in a place nobody touches. Photograph anything odd in place before you move it.
Hardware bug sweepers and what the evidence says
Handheld sweepers sold as K18, G318, G319 and Pro 10G cost roughly $20 to $200, and the fair question is whether they are worth buying. Unusually for this field there is a real answer.
What is actually in the box
A G318-class unit claims a frequency range of 1 MHz to 8000 MHz, sensitivity better than 0.03 mW and dynamic range above 73 dB, from the manufacturer’s own datasheet. Detection performance is usually quoted in square metres of coverage, which is a marketing unit rather than a physical one. Inside there are typically three separate functions: a broadband radio power detector, a ring of red LEDs with a viewing filter for spotting camera lenses, and sometimes a magnetic probe.
Two of those three are things a phone already does. The broadband radio stage is the only part of the box that a phone genuinely cannot replicate, and it is also the part that gives these devices their reputation for alarming at everything.
The numbers
| Method | Detection rate | False positive rate |
|---|---|---|
| Research time-of-flight method | 88.9% | 16.67% |
| K18 hardware detector, mode 1 | 62.3% | 26.9% |
| K18 hardware detector, mode 2 | 57.7% | 35.2% |
| Naked eye search | 46.0% | not reported |
Those figures come from the ACM SenSys 2021 study with 379 participants, and they measure camera detection rather than audio bug detection. We could find no equivalent peer-reviewed benchmark of consumer sweepers against audio bugs, which is itself worth knowing: the category sells confidence that nobody has published a measurement for. What the table does show is that a purpose-built detector missed roughly four devices in ten and raised a false alarm in a quarter to a third of trials.
Why they alarm constantly
Because a broadband power detector has no frequency selectivity whatsoever. Your own router, a neighbour’s router, a phone call in the next room, a smart meter, a nearby cell mast and a microwave oven all register as energy. The manuals say so and advise moving to a weak-signal area, advice that is close to useless inside a home. Learning to use one of these well takes practice, and the study authors noted that detectors of this class can be difficult to use correctly.
So should you buy one
If you want the genuine capability rather than the consumer version, the NYU work used a tinySA Ultra spectrum analyser at around $150, which is a real instrument with a real display rather than an LED bargraph. If the stakes are high enough to justify equipment, they are usually high enough to justify a professional, which is the next section. And if you are somewhere in between, twenty minutes of careful physical searching plus the software audit above will find more, for nothing.
When this stops being a DIY problem
Professional counter-surveillance, usually called TSCM, is a real discipline with real equipment: spectrum analysers, non-linear junction detectors that find electronics whether or not they are powered, thermal imaging and physical inspection by people who do it daily. It is not cheap and it is not always the right answer, but there are situations where a phone app is the wrong tool by a wide margin.
- Commercial stakes. Board rooms, legal proceedings, negotiations, anywhere the value of the information justifies the cost of planting a device properly.
- You have already found one device. Finding one is a strong reason to believe you have not found all of them, and it changes the search from speculative to targeted.
- A credible, specific threat rather than a general worry.
- A legal case where evidence has to be collected in a way that will survive challenge.
Equally, there are situations where the honest advice is that a sweep will not help. Persistent anxiety about being monitored, with no specific incident behind it, is not resolved by a clean sweep, because a clean sweep only ever means nothing was found. If that is where you are, the sweep is not the thing that will help, and there is no shame in saying so.
You found something. Stop and read this
Do not pull it out. The instinct is to rip the device out and destroy it. Both the Coalition Against Stalkerware and the National Network to End Domestic Violence advise against acting on that instinct, for two reasons.
It tells the person that you know. The Coalition’s survivor guidance states that removing monitoring may be detected by the abuser and could increase the abuse and harassment, and that removal should be attempted only if you believe it is safe.
It destroys the evidence. A device removed and unplugged is a device that can no longer be traced to anyone. Documenting first, keeping a dated incident log and coordinating with law enforcement early, where it is safe to do so, is what NNEDV’s Safety Net project recommends.
What to do instead. Leave the room before you contact anyone, because the device may be listening while you decide. Photograph it in place, wide and close, with enough of the surroundings to fix the location, and note the date and time. Then call someone who does this professionally: 1-800-799-7233 or text START to 88788 in the United States, 0808 2000 247 or 0808 802 0300 in the United Kingdom, 116 006 across the European Union. Whether to leave a device running or switch it off is part of a safety plan, not a technical decision, and it is one to make with an advocate rather than alone at midnight.
If the situation clearly does not involve a person you know, for example you have moved into a rented office and found equipment left by a previous tenant, none of the above applies and you can simply remove it. The distinction is the whole point, which is why we are not giving everyone the same instruction.
What we are building
Appsera · in development
Bug Detector for iPhone
We are building a detection app for iPhone. Given everything above, here is exactly what it can and cannot be, written before launch so you can hold us to it.
What it will do
- A device audit that walks you through the profile, Screen Time, permission, sharing and account checks in this page’s software section, in order, with a plain reading of what each result means. This is the check that most often finds something real.
- Local network listing with vendor names resolved where the address prefix is known, bounded by what iOS permits and labelled as bounded rather than presented as a full picture.
- A contact-range magnetometer probe with a baseline calibration step, for inspecting a specific suspicious object rather than sweeping a room.
- Bluetooth listing, which finds tracking tags rather than audio bugs but belongs in the same sweep.
- A guided room search, the zone method above, as a checklist you work through with a findings log of photos, notes and timestamps you can hand to someone else without retyping it.
- Honest negatives. A clean result will say which categories were ruled out and which were not even examined, because those are different statements and only one of them is reassuring.
What it will never claim
- Broadband RF sweeping. The hardware cannot do it, so there will be no fake spectrum display.
- Detecting a voice recorder, or a cellular bug between its transmission bursts.
- Detecting anything through a wall or inside metal.
- Ultrasonic or acoustic bug detection, which we found no evidence supports.
- That a clean scan means the room is clear. It means the scan found nothing, which is a much smaller claim and the only true one.
Not on the App Store yet. This page will link to it the day it ships.
We are writing the limits down before the app exists because the category is full of products that do the opposite, and an app that reports a detection it has no physical means of making is worse than no app. It converts a real worry into false confidence, and then the person stops looking.
Frequently asked questions
Can a phone app detect a listening device?
Not a transmitting one. A phone has no wideband radio receiver, so it cannot find an RF room transmitter, a GSM bug between bursts, or a voice recorder, which emits nothing at all. What a phone can genuinely do is audit itself for monitoring software, list devices on the local network, check a specific object at contact range with the magnetometer, and guide a structured physical search. That is a real toolkit and it is not a scanner.
Do bug detector apps work?
The parts that are grounded in a sensor work within narrow limits. The parts marketed as radio frequency sweeping do not work at all, because each radio in a phone sits behind a filter that discards everything outside its own band before software could ever see it, and no operating system exposes raw wideband signal strength. An app showing you a spectrum display is showing you an animation.
Is there a real RF signal detector app?
No, and there cannot be one on current phone hardware. Any app using that name is reading Wi-Fi, Bluetooth or cellular signal strength and relabelling it, reading the magnetometer, which is not a radio sensor, or generating a waveform. Genuine broadband detection needs a wide antenna and a power detector, which is what the handheld hardware units contain and what a phone deliberately does not.
How can I tell if my phone is bugged?
Check the things that monitoring software needs and cannot hide. On iPhone: Settings, General, VPN and Device Management for unknown profiles; Screen Time for a passcode you did not set; Privacy and Security, Microphone; the orange dot in the status bar; and your Apple ID device list. On Android: Security, Device admin apps; Special app access, particularly Usage access and Display over other apps; the privacy dashboard’s microphone history; and your Google account device list. Battery drain and heat are worth noticing but prove nothing on their own.
What is the best way to find a hidden microphone in a room?
A methodical physical search, in this order: everything with permanent mains power, then objects nobody ever moves, then the underside of furniture, then anything that arrived recently that you did not choose, then vents, junction boxes and the router. In the closest published comparison, a naked eye search found 46.0% of hidden devices in a 379-participant study while a widely sold hardware detector managed 62.3% with a 26.9% false positive rate. Careful looking is genuinely competitive with a cheap detector.
Can a bug work without any power source?
Not usefully in a home. Every practical listening device needs power, which is why anything with a permanent mains supply is the first place to search. Passive resonant devices requiring an external illuminating signal exist in the historical record but are not something a private individual encounters.
Will a bug detector app find a voice recorder?
No, and neither will a spectrum analyser costing a thousand times more. A recorder writes to internal memory and transmits nothing, so there is no emission to detect by any radio method. It is found by physical search, or by a non-linear junction detector in a professional sweep, which responds to the semiconductors inside it whether or not it is powered.
Do these apps drain the battery or need lots of permissions?
Continuous Bluetooth and network scanning does use power, and any app doing real work here needs Bluetooth and local network permission at minimum. Be suspicious of the reverse case: an app that asks for microphone, contacts or location access it has no stated use for is worth more scrutiny than the thing you downloaded it to find.
Is it legal to sweep for bugs, and to record what I find?
Searching your own home or your own vehicle is generally straightforward. Recording conversations, searching a property you do not control, and the legality of the device itself all vary substantially by jurisdiction, and in many places placing a listening device without consent is a criminal offence. We are not lawyers and this is not legal advice. If you find a device and you think a crime has been committed, that is a matter for the police.
What should I do first if I think I am being listened to?
Two things before you buy anything. Run the software audit on your phone, because that is where monitoring most often actually is. Then account for the microphones already in the room legitimately, including the smart speaker, the TV, the games console and the baby monitor, and check who controls those accounts. Only after both of those does a physical room search make sense.
Related reading
- GPS Bug Detector App: What Your Phone Can Actually Find in a Car · the four kinds of vehicle tracker, which two a phone can find, and the twenty-minute search.
- Hidden Camera Detector App: What Works, What Doesn’t, and How to Search a Room · lens reflection, infrared, and what the research actually measured.
Sources
Sami, Tan, Sun and Han, LAPD: Hidden Spy Camera Detection using Smartphone Time-of-Flight Sensors, ACM SenSys 2021, 379 participants. Satt et al., Detection of Hidden Cellular GPS Vehicle Trackers, USENIX VehicleSec 2025, NYU Tandon. Apple developer technote TN3111, iOS Wi-Fi API overview. Apple Support documentation on Personal Safety, device management profiles and the microphone indicator. Google Android support documentation on the privacy dashboard and special app access. Coalition Against Stalkerware survivor guidance. NNEDV Safety Net project guidance. Manufacturer datasheets for the G318 and G319 handheld detectors. Facts verified 28 August 2026.
Apple, iPhone, iOS, Google, Android and other product names are trademarks of their respective owners. Appsera is not affiliated with, endorsed by or connected to any of them. Product details, prices and platform behaviour described here were accurate in August 2026 and may have changed. Nothing on this page is legal advice.
