Google Early Access Exposed: Malicious Apps Hide in Plain Sight
Google's Early Access program is meant to help developers test their apps before launching them on the Google Play store. However, new research from Bitdefender Labs has found that this feature may also be allowing malicious apps to fly under the radar.
The study analyzed thousands of apps in Google's Early Access program and discovered a number of suspicious applications, including fake casino games, misleading utilities, and apps using recognizable third-party trademarks. Many of these apps were promoted on social media platforms like TikTok and Facebook, and some even used AI-generated deepfakes of celebrities to advertise themselves.
Bitdefender's Security Analyst Silviu Stahie warned that the lack of publicly available reviews for Early Access apps makes it difficult for users to identify problematic software. He noted that some of the suspicious applications requested unusual permissions or exhibited behavior that could create a more serious problem if installed on an employee's Android device.
For example, one QR scanner app asked to become the phone's launcher, which is an unusual request and potentially a sign of malicious intent. Stahie explained that this could allow the app to silently load hidden web views and continuously click on advertisements, or even display fake login screens and intercept taps.