{"id":248615,"date":"2025-07-08T18:03:11","date_gmt":"2025-07-08T18:03:11","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/248615\/"},"modified":"2025-07-08T18:03:11","modified_gmt":"2025-07-08T18:03:11","slug":"google-could-soon-protect-your-android-device-from-dangerous-pwas-and-webapks","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/248615\/","title":{"rendered":"Google could soon protect your Android device from dangerous PWAs and WebAPKs"},"content":{"rendered":"<p><img class=\"e_ph\" decoding=\"async\" loading=\"eager\"  title=\"Google Play Protect Apps scanned\"  alt=\"Google Play Protect Apps scanned\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2025\/07\/Google-Play-Protect-Apps-scanned-scaled.jpg\"\/><\/p>\n<p>Aamir Siddiqui \/ Android Authority<\/p>\n<p>TL;DR<\/p>\n<ul>\n<li>Google could soon extend Play Protect to scan PWAs and WebAPKs during installation.<\/li>\n<li>This new feature could protect users from malicious PWAs used for phishing and data theft.<\/li>\n<\/ul>\n<p>Google has been silently protecting most Android devices through <a href=\"https:\/\/www.androidauthority.com\/play-protect-disable-calls-3493200\/\" target=\"_blank\" rel=\"noopener\">Google Play Protect<\/a>, scanning the apps that users have installed, and warning them of nefarious ones. While platform-native apps remain the most popular method to access a service, Progressive Web Apps (PWAs) remain a good web-centric alternative. Unfortunately, bad actors will exploit any medium they can lay their hands on, and it becomes <a href=\"https:\/\/www.androidauthority.com\/android-16-advanced-protection-hands-on-3569651\/\" target=\"_blank\" rel=\"noopener\">imperative for Google to protect its user base<\/a>. We\u2019ve now spotted code that suggests that Google Play Protect will start scanning Progressive Web Apps during installation to check for security issues, adding one more layer of security for users.<\/p>\n<p> You&#8217;re reading an <strong>Authority Insights<\/strong> story on Android Authority. Discover <a href=\"https:\/\/www.androidauthority.com\/tag\/authority-insights\/\" target=\"_blank\" rel=\"noopener\"><strong>Authority Insights<\/strong><\/a> for more exclusive reports, app teardowns, leaks, and in-depth tech coverage you won&#8217;t find anywhere else.<\/p>\n<p>An\u00a0<b data-stringify-type=\"bold\">APK teardown<\/b> helps predict features that may arrive on a service in the future based on work-in-progress code. However, it is possible that such predicted features may not make it to a public release.<\/p>\n<p>Google Play Store v46.9.20-31 includes the following code:<\/p>\n<p>Code<\/p>\n<p>Copy TextPlayProtect__enable_gpp_install_verification_for_pwa<\/p>\n<p>Here, PWA refers to Progressive Web Apps. The flag would enable Play Protect to verify the PWAs during their installation. Yes, PWAs can be installed on a device, usually through an \u201cAdd to Home screen\u201d button from the browser app. If you do this through Chrome on Android, you get a WebAPK, which gives the PWA a space in your app drawer (in addition to the space on the home screen) and integrates it more deeply into the Android system than a regular PWA.<\/p>\n<p>We also spotted code bits hinting at WebAPK scanning:<\/p>\n<p><img class=\"e_ph\" decoding=\"async\" loading=\"lazy\"  title=\"Google Play Protect WebAPK scanning 2\"  alt=\"Google Play Protect WebAPK scanning 2\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2025\/07\/Google-Play-Protect-WebAPK-scanning_2.jpg\"\/><\/p>\n<p>AssembleDebug \/ Android Authority<\/p>\n<p>While the code mentions scanning PWAs and WebAPKs, it doesn\u2019t explain why Google would want to do so.\u00a0There have been reports of malicious actors using <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/be-careful-what-you-pwish-for-phishing-in-pwa-applications\/\" target=\"_blank\" rel=\"noopener\">PWAs<\/a> and <a href=\"https:\/\/www.linkedin.com\/pulse\/using-webapk-technology-phishing-attacks-csirt-knf\/\" target=\"_blank\" rel=\"noopener\">WebAPKs<\/a> to phish and steal user information, so it\u2019s possible that Google could be aiming to protect its users from such phishing attempts by proactively warning them whenever a bad PWA or WebAPK is installed.<\/p>\n<p>There are plenty of other questions to answer, like how PWA and WebAPK scanning would work if this does roll out. For usual apps distributed through the Play Store, Google already has an extensive database of apps against which it can check for tampering and other threats through Play Protect. Such a database is difficult to envisage for the entirety of the PWA universe, so we\u2019re curious to know how Google plans to approach this if it goes ahead.<\/p>\n<p>PWA and WebAPK scanning are not currently available in Play Protect, and Google has not announced the feature either. We\u2019ll update you when we learn more.<\/p>\n<p><strong>Got a tip? Talk to us!<\/strong>\u00a0Email our staff at <a class=\"c-link\" href=\"https:\/\/www.androidauthority.com\/google-play-protect-pwa-webapk-scanning-apk-teardown-3574977\/mailto:news@androidauthority.com\" rel=\"noopener noreferrer\" data-stringify-link=\"mailto:tips@androidauthority.com\" data-sk=\"tooltip_parent\" aria-haspopup=\"menu\" target=\"_blank\">news@androidauthority.com<\/a>. You can stay anonymous or get credit for the info, it&#8217;s your choice.<\/p>\n","protected":false},"excerpt":{"rendered":"Aamir Siddiqui \/ Android Authority TL;DR Google could soon extend Play Protect to scan PWAs and WebAPKs during&hellip;\n","protected":false},"author":2,"featured_media":248616,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3159],"tags":[2240,867,3597,34415,54334,547,53,16,15],"class_list":{"0":"post-248615","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-authority-insights","9":"tag-google","10":"tag-google-play","11":"tag-google-play-services","12":"tag-google-play-store","13":"tag-mobile","14":"tag-technology","15":"tag-uk","16":"tag-united-kingdom"},"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/248615","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=248615"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/248615\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/248616"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=248615"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=248615"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=248615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}