
On Thursday, Google introduced a new “advanced method” for sideloading Android apps. To balance accessibility and security, installing apps from unverified developers will now require a 24-hour waiting period.
These updates are related to a developer verification requirement announced last year. The requirement mandates that all Android apps be registered by verified developers to be installable on certified Android devices. Google stated this measure aims to identify and stop malicious actors from distributing malware more quickly.
This also addresses situations where cybercriminals deceive users sideloading apps into granting excessive permissions, allowing them to disable Play Protect, the built-in anti-malware protection on Google-certified Android devices.
However, the mandatory registration has been criticized by over 50 app developers and marketplaces, including F-Droid, Brave, The Electronic Frontier Foundation, Proton, The Tor Project, and Vivaldi. They expressed concerns that it could create obstacles and discourage new developers, while also raising privacy and surveillance issues due to a lack of clarity regarding required personal information, data storage, security, usage, and potential government access or legal proceedings.
To address some of these concerns, Google has highlighted that the new advanced method lets experienced users retain the ability to sideload apps from unverified developers through a one-time process involving these steps:
“We believe the 24-hour waiting period makes it significantly more difficult for attackers to maintain their attacks,” Sameer Samat, Android Ecosystem President, told Ars Technica. “During that time, you are more likely discover that a loved one is not really held in jail or that your bank account is not really under attack.”
Google also plans to offer free “limited distribution accounts” for hobbyist developers and students to share apps with up to 20 devices without needing to provide identification or pay a registration fee.
It’s important the new process does not affect installations through the Android Debug Bridge (ADB). Limited distribution accounts and the user advanced flow will be available in August 2026, before the new developer verification becomes active the following month.
“We understand a ‘one size fits all’ approach isn’t suitable for our diverse ecosystem,” Google stated. “We want to ensure that identity verification isn’t a barrier to entry, so weâre providing different paths to fit your specific needs.”
This update coincides with the discovery of a new Android malware, Perseus, targeting users in Turkey and Italy for device takeover and financial fraud.
Over the past four months, at least 17 Android malware families have been identified, including FvncBot, SeedSnatcher, ClayRat, Wonderland, Cellik, Frogblight, NexusRoute, ZeroDayRAT, Arsink (and its improved variant SURXRAT), deVixor, Phantom, Massiv, PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and Oblivion RAT.
#app #delays #from #google #installs #news #sources #unknown — News
© Bulletproof Servers. All rights reserved.