Hands-on with Google's real-time scanning in Play Protect for sideloaded apps: it didn't restrict five predatory loan apps and two fake apps from installing
Here's our hands-on review of the new Android security feature — Android's in-built security engine Google Play Protect …
Context & Ripple Effects
Google positioned Play Protect as Android's built-in malware screen years ago, then introduced code-level real-time scanning for unknown sideloaded apps in an India-first experimental rollout. This test matters because it examines whether that added checkpoint changes the outcome for apps obtained outside Play.
The result also sits against prior evidence that Play Protect's detection performance has been uneven, including a research comparison of malicious-app detection rates. The gap is especially consequential where users depend on the prompt as a meaningful warning before installation.
First-order effects
- The tested predatory loan and fake apps could still be installed after Play Protect's real-time scan, leaving sideloading users without the expected immediate block.
- Google's new scanning prompt is shown to be an incomplete safeguard in the tested cases, rather than a reliable installation gate.
Second-order effects
- Google faces pressure to improve the detection and enforcement path behind the scan prompt, particularly before expanding an experimental India rollout.
- Sideloaded-app distributors and users cannot treat a successful Play Protect scan as proof that an app is legitimate; security products and advice aimed at these users retain a role alongside the platform check.
Third-order effects
- The episode underscores a broader limitation of app-security systems: adding real-time analysis does not by itself protect users unless detection is paired with dependable intervention against harmful behavior.
- If similar misses persist as scanning expands, Android security may increasingly be judged on measurable prevention outcomes rather than on the presence of scanning features or prompts.
The trend: Mobile platform security is moving toward continuous, code-level scrutiny of sideloaded software, with trust increasingly determined by how consistently those systems stop abuse.