Google’s Early Access is creating a blind spot for malicious apps

Wait 5 sec.

Google’s Early Access program is meant to give developers a place to release unfinished apps, gather feedback and handle bugs before a full launch.But new research from Bitdefender Labs suggests the feature may also be giving potentially deceptive applications an unusual advantage, as users cannot publicly rate or review an app while it remains in Early Access.An analysis of Google Play applications installed by Bitdefender users identified thousands of Early Access apps that appeared to include fake casino and reward games, potentially misleading utilities and applications using recognizable third-party trademarks. Many were also promoted through TikTok, Facebook, and other social platforms, including advertisements featuring AI-generated deepfakes of celebrities and other public figures.For enterprises, the concern isn’t simply that an employee might waste time on a fake casino game.Bitdefender Security Analyst Silviu Stahie said some of the seemingly ordinary utilities the company examined requested unusual permissions or exhibited behavior that could create a much more serious problem if such an application were installed on an employee’s Android device.A QR scanner wanted to become the phone’s launcherStahie told CSO that most of the applications discovered were primarily focused on serving advertisements, but some raised more serious concerns.In one case, a QR-reading application attempted to persuade the user to replace the official Android launcher on a Pixel phone. That is an unusual request for an application whose basic function is scanning QR codes, Stahie noted.“A QR code scanner only requires Camera access,” he said, adding that it may optionally need access to photos or storage for scanning saved images. “It has zero legitimate reasons to act as a home screen replacement. The most likely scenario is that the developer wanted the app to run continuously in the background.”As a launcher, it could silently load hidden web views to continuously click on advertisements, a technique known as Clickjacking.But the same behavior could potentially be used to display fake login screens, intercept taps, and even capture two-factor authentication codes delivered through notifications, Stahie said.The research found suspicious applications across categories including PDF readers, QR scanners, phone trackers and utility applications, alongside casino, reward and “earn money” applications. Some have accumulated thousands of installs or more while remaining in Early Access.Enterprises have ways to limit the riskBitdefender said it cannot determine whether the devices on which these applications were observed were being used for work or personal purposes. But Stahie argues that the unusual permissions themselves should be treated as a warning sign.“If one of these apps becomes popular, the developers could push an update to make them extremely dangerous and evolve into a much more malicious threat,“ he said.That possibility is concerning because Early Access removes one of the mechanisms users normally rely on to identify problematic software. A conventional Play Store application can quickly accumulate negative reviews when users discover misleading behavior. With Early Access, those warnings aren’t publicly available.For organizations allowing employees to use personal Android devices for work, Stahie recommends using the “Android Enterprise Work Profile” feature that separates work applications and data from employees’ personal environment. Companies can use a Device Policy Controller, such as an enterprise management solution, to provision the work profile on employee-owned devices.“If the company supplies and owns the phone, then the organization owns the full operating system, but provisions an isolated Work Profile alongside a Personal Profile,” Stahie said. “Everything related to work, email clients, and any other apps runs in its own separate sandbox, and the user can’t install anything they shouldn’t in the Work Profile.”While this is not a “perfect solution,” Stahie believes that, when paired with dedicated mobile security and employee training around suspicious applications, it can help.Google itself allows Workspace administrators to turn Early Access applications off for their entire organization or restrict access by organizational unit or group, giving enterprises a way to limit exposure if they deem the risk too high.