Google Implements New Security Measures for Android Sideloading
Ravie Lakshmanan, March 20, 2026 – Google has announced a new security measure aimed at reducing the risk of malware and scams on Android devices. The tech giant is introducing an advanced flow that requires users to wait 24 hours before installing apps from unverified developers.
Background
Last year, Google mandated developer verification for all Android apps in a bid to enhance security. However, this move has faced criticism from over 50 app developers and marketplaces who argue that it creates barriers to entry and raises privacy concerns.
New Security Measures
The new advanced flow includes the following steps:
- Enable developer mode in system settings.
- Confirm that the user is acting voluntarily and not being coached by someone else.
- Restart the phone and re-authenticate to prevent scammers from monitoring actions.
- Wait for 24 hours, during which users must confirm their intention using biometric authentication or a device PIN.
After completing these steps, users can install apps from unverified developers either indefinitely or for up to seven days.
Additional Support for Developers
To address concerns about the developer verification requirements, Google plans to offer free limited distribution accounts. These will allow hobbyist developers and students to share apps with up to 20 devices without providing government-issued IDs or paying registration fees.
Implementation Timeline
The advanced flow for users and limited distribution accounts for students and hobbyists are scheduled to be available in August 2026, before the new developer verification requirements take effect in September.
Context of Recent Threats
This development comes amid a surge in Android malware. A new threat called Perseus is actively targeting users in Turkey and Italy with device takeover (DTO) and financial fraud. Over the past four months, at least 17 Android malware families have been detected.
元記事: https://thehackernews.com/2026/03/google-adds-24-hour-wait-for-unverified.html
