Google’s Early Access is creating a blind spot for malicious apps
Summary
Google's Early Access program allows developers to release unfinished apps without public reviews, but research from Bitdefender Labs found this creates a security risk by hiding malicious or deceptive applications from user scrutiny. Some Early Access apps request suspicious permissions like becoming a phone launcher (which could enable clickjacking, a technique for silently triggering unwanted actions, or capturing login credentials), while others use fake casino games and AI-generated deepfakes to deceive users.
Solution / Mitigation
For organizations with employees using personal Android devices for work, Bitdefender recommends using the "Android Enterprise Work Profile" feature to separate work applications and data from the personal environment. Companies can use a Device Policy Controller (an enterprise management solution) to provision the work profile on employee-owned devices, isolating work-related apps like email clients in a separate sandbox where users cannot install unauthorized applications. If the company owns the phone, the organization can provision an isolated Work Profile alongside a Personal Profile on the device.
Classification
Original source: https://www.csoonline.com/article/4221068/googles-early-access-is-creating-a-blind-spot-for-malicious-apps.html
First tracked: September 11, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 95%