LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewMedusa ransomware gang has hit over 500 organizations, CISA warnsCritical RCE flaw in Windows IKE Extension now actively exploitedOracle August 2026 Critical Security Patch Update Addresses 925 CVEs
security

Sideloading on Android: What it is, why it’s risky, and how to do it more safely

With the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.

zeroday.news ·

Google has begun rolling out an "Advanced Flow" feature designed to enhance the safety of installing Android applications from developers who have not completed the platform's identity verification process. This new security measure aims to mitigate risks associated with "sideloading," the practice of installing apps from sources other than the Google Play Store.

Sideloading allows Android users to install applications from various sources, including a developer's website, alternative app marketplaces, enterprise portals, or directly shared files. This flexibility is a core strength of Android, enabling access to apps unavailable in certain regions, open-source software, beta versions, or specialized enterprise tools. However, it also introduces significant security risks, as these apps bypass some of the vetting and safeguards present in official app stores.

While the Google Play Store employs review processes, policy enforcement, developer controls, and Google Play Protect to reduce risks, it is not entirely immune to threats. Google reported blocking over 1.75 million policy-violating apps and banning more than 80,000 developer accounts in 2023. Despite these efforts, malicious apps can still appear, including Trojans disguised as utilities or games, adware, subscription traps, data-harvesting apps, and "sleeper apps" that change behavior after initial review. Google Play Protect scans both Play Store apps and sideloaded applications, but it serves as one layer of defense, not a complete solution.

The primary difference between installing from a recognized store and sideloading an APK lies in the chain of trust. When sideloading, users may have fewer assurances regarding the app's creator, whether the file has been tampered with, the legitimacy of the download site, the authenticity of future updates, and whether they are being manipulated by scammers. Social engineering is a significant factor, with attackers often impersonating banks, delivery services, government agencies, or recruiters to pressure victims into installing malicious apps or disabling security features. Legitimate organizations should not instruct users to install APKs or weaken Android security settings via unexpected calls or messages.

To sideload more safely, users are advised to proceed only when they have a specific, self-initiated reason. It is crucial to download apps directly from the developer's official website, avoiding sponsored search results, random download portals, links from strangers, or lookalike domains. Independent verification of the developer through their official website, documentation, public code repositories, and trusted community channels is recommended. Preferring established third-party repositories with strong reputations for provenance and signature verification is also beneficial. Advanced users can compare an APK's signing certificate or cryptographic hash against values published by the developer to detect fakes.

Crucially, users should never install apps under pressure. Any urgent, secretive, or financially incentivized request to install an app, especially from a claimed bank, government, or employer, should be treated as suspicious. Maintaining Google Play Protect as enabled is important, as it scans apps during and after installation. Users should also carefully review app permissions both before and after installation, exercising caution if an app requests excessive access to sensitive features like accessibility services, SMS messages, notifications, device administration, contacts, or screen recording. Keeping Android and all applications updated with the latest security fixes and using reputable mobile security software can provide additional protection. Regularly removing permissions and uninstalling unused or untrusted apps is also a good practice.

Google's new Advanced Flow specifically targets social engineering tactics. Instead of a simple one-tap override, it requires users to enable developer mode in system settings, complete a quick safety check to ensure they are not being coerced, and restart their device to disrupt any active remote access or phone calls from scammers. A key component is a one-day delay, after which users must confirm the change using biometrics or their device PIN. This delay is designed to break the urgency relied upon by scammers, providing time for reflection. Once the process is completed, users can choose to allow installs from unverified developers for seven days or indefinitely.

While developer verification establishes accountability by linking an app to a verified identity, it does not guarantee an app's benign nature or suitability for all users. The ultimate responsibility lies with the user to scrutinize app sources, understand requested permissions, and refuse installation if rushed or pressured by an external party, regardless of whether the app originates from the Google Play Store or an external source.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]

ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.