A Google spokesperson announced on Reddit that it has started rolling out the first version of its Advanced Flow, designed to make installing apps from unverified developers safer.
Let us explain what sideloading is, why Google Play is not 100% safe, what to look for when you’re sideloading so you can do it more safely, and how Google’s Advanced Flow helps with that.
What is sideloading?
Sideloading lets Android users install apps from outside Google Play. It can be useful, but it also creates opportunities for scams and malware.
Android’s openness is one of its enduring strengths. You are not limited to a single app store: You can install apps from a developer’s website, an alternative marketplace, an enterprise portal, or a file shared directly with you.
That is called sideloading. It is not automatically dangerous, but it removes some of the guardrails that come with conventional app-store distribution. Getting apps from the Google Play Store itself is no guarantee of safety, but there is at least some vetting. Google says it blocked more than 1.75 million policy-violating apps from being published in 2025 and banned more than 80,000 developer accounts associated with harmful apps.
There are several reasons for sideloading:
- The developer distributes an app directly from its own website
- An app is unavailable in your country or on Google Play
- An alternative app repository offers what you’re after, for example open-source software
- You need an enterprise, beta, or specialized app
- You want to install a version that is not currently offered through Google Play
But malware authors and online scammers use the same flexibility. They may impersonate banks, delivery services, government agencies, crypto platforms, news readers, or job recruiters, then urge victims to install an app to “secure” an account, receive a payment, or resolve an invented problem.
Google Play is not a free pass
Google Play has review processes, policy enforcement, developer controls, and Google Play Protect. It also runs ongoing checks after an app is published. Those measures meaningfully reduce risk, but they do not make every listing harmless or every developer trustworthy.
Threats that can still surface through official channels include:
- Trojans disguised as useful utilities, games, or financial apps
- Adware and apps that misrepresent their behavior
- Subscription traps and deceptive billing practices
- Data-harvesting apps that request more access than they need
- Sleeper apps that change behavior after passing an initial review
Google Play Protect checks Play Store apps before download and also scans apps from other sources. It can warn about, disable, or remove potentially harmful apps, but it should be viewed as one layer of security, not a substitute for scrutinizing an app before installing it.
Mobile protection, anywhere, anytime.
In short, “available on Google Play” is a positive signal, not a security verdict.
Why sideloading requires attention
The main difference between installing from a recognized store and downloading an APK from elsewhere is not simply the file format. It is the trust chain.
When you sideload, you may have fewer assurances about:
- Who created the app
- Whether the file has been altered or repackaged
- Whether the download site is impersonating a legitimate developer
- Whether you will receive genuine updates
- Whether a scammer is manipulating you into disabling security protections
Social engineering is often the decisive factor. A convincing caller, pop-up, text, or chat message may insist that installing an app is urgent. The attacker’s goal is often to make the victim bypass warnings before they have time to question the request.
Treat any unexpected request to install an app as suspicious, especially when it comes with urgency, secrecy, a promise of money, or a claim that your bank, government, employer, or device provider requires it.
A legitimate bank, government agency, law-enforcement organization, or technical-support provider should not call or message you and instruct you to install an APK or weaken Android security settings.
How to sideload more safely
Sideload only when you have a specific reason for it, and make sure the decision came from you rather than an unexpected message or phone call.
- Start at the developer’s official site. Don’t use sponsored search results, random download portals, links sent by strangers, or lookalike domains.
- Verify the developer independently. Check the publisher’s official website, documentation, public code repository, and trusted community channels. The information supplied on the download page alone is not enough.
- Prefer established repositories. If an app is distributed outside Google Play, use a source with a strong reputation for provenance and signature verification where possible. For advanced users, it can be useful to compare an APK’s signing certificate or cryptographic hash against a value published by the developer. That is not practical for everyone, but it can help detect fakes.
- Do not install apps under pressure. End the call, close the chat, and independently research the claimed organization using contact details you find yourself.
- Keep Google Play Protect enabled. It scans apps during installation and periodically afterward, including apps installed from outside Google Play.
- Review permissions before and after installation. Be especially cautious if a simple app wants access to accessibility services, SMS messages, notifications, device administration, contacts, or screen recording.
- Keep Android and apps updated. Security fixes can protect against both operating-system flaws and known malicious app behavior.
- Use reputable mobile security software. A separate security layer can help identify risky behavior and provide additional visibility into potentially unwanted or malicious apps.
- Remove permissions and uninstall apps you no longer trust or use. An app that seemed harmless at installation can become a liability if its developer abandons it or changes direction.
How Google’s new Advanced Flow helps
Google is rolling out Advanced Flow for installing apps from developers that have not completed Android’s new identity-verification process. The feature is intended for users who understand the risks of installing unverified software but still need that flexibility.
The design is notable because it targets social-engineering attacks as well as malware. Instead of allowing an immediate, one-tap override, the flow requires users to:
- Enable developer mode in system settings. This is easy enough and helps prevent accidental or one-tap bypasses often used in high-pressure scams.
- Complete a quick safety check to make sure that no one is talking you into turning off your security. Scammers often pressure victims into disabling protections.
- Restart your device, which cuts off any remote access or active phone calls a scammer might be using to guide you.
- Wait one day, then confirm the change using biometrics, such as fingerprint or face unlock, or your device PIN. This one-time, one-day delay breaks the urgency scammers rely on, giving you time to think.
Once you have completed the process, you can choose to allow installs from unverified developers for seven days or indefinitely.
Advanced Flow does not mean Google Play is risk-free, nor does it make unverified apps inherently malicious. Developer verification establishes accountability: It connects an app to a verified developer identity, but it does not establish that every app is benign or suitable for every user.
At the end of the day, it’s up to you. Install apps because you chose them after checking the source, not because someone else manufactured an emergency.
Whether an app comes from Google Play or an external source, pause before installing. Check who made it, why it needs the permissions it asks for, whether the download route is trustworthy, and refuse when a stranger is trying to rush you. That little friction is a feature, not just a nuisance.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Download for iOS → Download for Android →

