Android and Google Play comprise a vibrant ecosystem with billions of customers across the globe and thousands and thousands of useful apps. Maintaining this ecosystem secure for customers and builders stays our prime precedence. Nevertheless, like every flourishing ecosystem, it additionally attracts its share of dangerous actors. That’s why yearly, we proceed to spend money on extra methods to guard our group and combat dangerous actors, so customers can belief the apps they obtain from Google Play and builders can construct thriving companies.
Final 12 months, these investments included AI-powered risk detection, stronger privateness insurance policies, supercharged developer instruments, new industry-wide alliances, and extra. In consequence, we prevented 2.36 million policy-violating apps from being revealed on Google Play and banned greater than 158,000 dangerous developer accounts that tried to publish dangerous apps.
However that was simply the beginning. For extra, check out our latest highlights from 2024:
Google’s superior AI: serving to make Google Play a safer place
To maintain out dangerous actors, we have now at all times used a mix of human safety specialists and the most recent threat-detection expertise. In 2024, we used Google’s superior AI to enhance our methods’ skill to proactively determine malware, enabling us to detect and block dangerous apps extra successfully. It additionally helps us streamline assessment processes for builders with a confirmed monitor report of coverage compliance. Right now, over 92% of our human evaluations for dangerous apps are AI-assisted, permitting us to take faster and extra correct motion to assist forestall dangerous apps from turning into out there on Google Play.
That’s enabled us to cease extra dangerous apps than ever from reaching customers by means of the Play Retailer, defending customers from dangerous or malicious apps earlier than they’ll trigger any injury.
Working with builders to reinforce safety and privateness on Google Play
To guard consumer privateness, we’re working with builders to scale back pointless entry to delicate knowledge. In 2024, we prevented 1.3 million apps from getting extreme or pointless entry to delicate consumer knowledge. We additionally required apps to be extra clear about how they deal with consumer data by launching new developer necessities and a brand new “Knowledge deletion” possibility for apps that assist consumer accounts and knowledge assortment. This helps customers handle their app knowledge and perceive the app’s deletion practices, making it simpler for Play customers to delete knowledge collected from third-party apps.
We additionally labored to make sure that apps use the strongest and newest privateness and safety capabilities Android has to supply. Each new model of Android introduces new safety and privateness options, and we encourage builders to embrace these developments as quickly as attainable. Because of partnering intently with builders, over 91% of app installs on the Google Play Retailer now use the most recent protections of Android 13 or newer.
Safeguarding apps from scams and fraud is an ongoing battle for builders. The Play Integrity API permits builders to verify if their apps have been tampered with or are operating in probably compromised environments, serving to them to forestall abuse like fraud, bots, dishonest, and knowledge theft. Play Integrity API and Play’s automated safety helps builders make sure that customers are utilizing the official Play model of their app with the most recent safety updates. Apps utilizing Play integrity options are seeing 80% decrease utilization from unverified and untrusted sources on common.
We’re additionally continuously working to enhance the security of apps on Play at scale, akin to with the Google Play SDK Index. This software gives insights and knowledge to assist builders make extra knowledgeable choices concerning the security of an SDK. Final 12 months, along with including 80 SDKs to the index, we additionally labored intently with SDK and app builders to handle potential SDK safety and privateness points, serving to to construct safer and safer apps for Google Play.
Google Play’s multi-layered protections in opposition to dangerous apps
To create a trusted expertise for everybody on Google Play, we use our SAFE ideas as a information, incorporating multi-layered protections which might be at all times evolving to assist preserve Google Play secure. These protections begin with the builders themselves, who play a vital function in constructing safe apps. We offer builders with best-in-class instruments, greatest practices, and on-demand coaching sources for constructing secure, high-quality apps. Each app undergoes rigorous assessment and testing, with solely permitted apps allowed to look within the Play Retailer. Earlier than a consumer downloads an app from Play, customers can discover its consumer evaluations, rankings, and Knowledge security part on Google Play to assist them make an knowledgeable resolution. And as soon as put in, Google Play Defend, Android’s built-in safety safety, helps to protect their Android gadget by repeatedly scanning for malicious app habits.
Enhancing Google Play Defend to assist preserve customers secure on Android
Whereas the Play Retailer gives best-in-class safety, we all know it’s not the one place customers obtain Android apps – so it’s essential that we additionally defend Android customers from extra generalized cellular threats. To do that in an open ecosystem, we’ve invested in refined, real-time defenses that defend in opposition to scams, malware, and abusive apps. These clever safety measures assist to maintain customers, consumer knowledge, and units secure, even when apps are put in from varied sources with various ranges of safety.
Google Play Defend mechanically scans each app on Android units with Google Play Providers, irrespective of the obtain supply. This built-in safety, enabled by default, gives essential safety in opposition to malware and undesirable software program. Google Play Defend scans greater than 200 billion apps each day and performs real-time scanning on the code-level on novel apps to fight rising and hidden threats, like polymorphic malware. In 2024, Google Play Defend’s real-time scanning recognized greater than 13 million new malicious apps from exterior Google Play1.
Google Play Defend is at all times evolving to fight new threats and defend customers from dangerous apps that may result in scams and fraud. Listed here are among the new enhancements that are actually out there globally on Android units with Google Play Providers:
- Reminder notifications in Chrome on Android to re-enable Google Play Defend: In keeping with our analysis, greater than 95 p.c of app installations from main malware households that exploit delicate permissions extremely correlated to monetary fraud got here from Web-sideloading sources like net browsers, messaging apps, or file managers. To assist customers keep protected when searching the net, Chrome will now show a reminder notification to re-enable Google Play Defend if it has been turned off.
- Further safety in opposition to social engineering assaults: Scammers might manipulate customers into disabling Play Defend throughout calls to obtain malicious Web-sideloaded apps. To forestall this, the Play Defend app scanning toggle is now quickly disabled throughout cellphone or video calls. This safeguard is enabled by default throughout conventional cellphone calls in addition to throughout voice and video calls in common third-party apps.
- Mechanically revoking app permissions for probably harmful apps: Since Android 11, we’ve taken a proactive strategy to knowledge privateness by mechanically resetting permissions for apps that customers have not used shortly. This ensures apps can solely entry the info they really want, and customers can at all times grant permissions again if obligatory. To additional improve safety, Play Defend now mechanically revokes permissions for probably dangerous apps, limiting their entry to delicate knowledge like storage, pictures, and digital camera. Customers can restore app permissions at any time, with a affirmation step for added safety.
Google Play Defend’s enhanced fraud safety pilot analyzes and mechanically blocks the set up of apps that will use delicate permissions steadily abused for monetary fraud when the consumer makes an attempt to put in the app from an Web-sideloading supply (net browsers, messaging apps, or file managers).
Constructing on the success of our preliminary pilot in partnership with the Cyber Safety Company of Singapore (CSA), extra enhanced fraud safety pilots are actually lively in 9 areas – Brazil, Hong Kong, India, Kenya, Nigeria, Philippines, South Africa, Thailand, and Vietnam.
In 2024, Google Play Defend’s enhanced fraud safety pilots have shielded 10 million units from over 36 million dangerous set up makes an attempt, encompassing over 200,000 distinctive apps.
By piloting these new protections, we will proactively fight rising threats and refine our options to thwart scammers and their more and more refined fraud makes an attempt. We sit up for persevering with to accomplice with governments, ecosystem companions, and different stakeholders to enhance consumer protections.
App badging to assist customers discover apps they’ll belief at a look on Google Play
In 2024, we launched a brand new badge for presidency builders to assist customers world wide determine official authorities apps. Authorities apps are sometimes targets of impersonation because of the extremely delicate nature of the info customers present, giving dangerous actors the power to steal identities and commit monetary fraud. Badging verified authorities apps is a vital step in serving to join folks with secure, high-quality, helpful, and related experiences. We accomplice intently with world governments and are already exploring methods to construct on this work.
We additionally not too long ago launched a new badge to assist Google Play customers uncover VPN apps that take additional steps to show their robust dedication to safety. We enable builders who adhere to Play security and safety tips and have handed a further impartial Cell Software Safety Evaluation (MASA) to show a devoted badge within the Play Retailer to focus on their elevated dedication to security.
Collaborating to advance app safety requirements
Along with our partnerships with governments, builders, and different stakeholders, we additionally labored with our {industry} friends to guard your entire app ecosystem for everybody. The App Protection Alliance, in partnership with fellow steering committee members Microsoft and Meta, not too long ago launched the ADA Software Safety Evaluation (ASA) v1.0, a brand new customary to assist builders construct safer cellular, net, and cloud purposes. This customary gives clear steerage on defending delicate knowledge, defending in opposition to cyberattacks, and finally, strengthening consumer belief. This marks a big step ahead in establishing industry-wide safety greatest practices for software growth.
All builders are inspired to assessment and adjust to the brand new cellular safety customary. You’ll see this customary in motion for all service apps pre-installed on future Pixel cellphone fashions.
Trying forward
This 12 months, we’ll proceed to guard the Android and Google Play ecosystem, constructing on these instruments and sources in response to consumer and developer suggestions and the altering panorama. As at all times, we’ll preserve empowering builders to construct safer apps extra simply, streamline their coverage expertise, and defend their companies and customers from dangerous actors.
1 Primarily based on Google Play Defend 2024 inner knowledge.