started · updated
Google introduces stricter Android security and developer verification
Google is implementing significant security changes to the Android ecosystem to combat malware and unauthorized app installations. A key component is the introduction of ‘Advanced Flow,’ a process designed to complicate sideloading—the installation of apps from sources outside the official Google Play Store. To use this feature, users will need to enable Developer Mode, pass security checks, restart their device, and wait a mandatory 24-hour period before the installation can proceed. This delay aims to prevent social engineering attacks where scammers pressure users into immediate actions.
Additionally, Google will require app developers to undergo identity verification to distribute software on certified Android devices. This policy, which applies to third-party stores like the Galaxy Store and OPPO App Market, is scheduled to begin in Brazil, Indonesia, Singapore, and Thailand by September 2026, with a global rollout planned for 2027. Developers will be required to provide official identification and pay a fee.
These measures come amid rising threats from sophisticated malware. Security researchers have identified ‘Manic,’ which can steal PINs and credentials even when a device is offline, and ‘ToxicPanda 2.0,’ which targets financial and cryptocurrency applications by abusing Android’s accessibility and VPN services. Google is also expanding its ‘SafetyCore’ and ‘ContentSafetyManager’ technologies to allow authorized apps to monitor sensitive content, such as blurring explicit images in messaging apps, directly on the device.
Entities
Amazon Web Services · Android · Google · ThreatFabric · Zimperium