Google slaps a 24-hour brake on rogue android apks
Google just turned sideloading
into a forced detox: tap an APK from an unverified dev today and your phone will stonewall you until tomorrow.The cooldown is part of a six-step ritual that starts with digging into Developer Options, ends with a final scare screen, and in between demands a reboot that severs any sneaky screen-share a scammer might be running. One mis-tap and you’re back to square one.
Inside google’s friction factory
The company swears the maze is aimed at boiler-room crooks who panic victims into “install this update NOW” scams. A forced 24-hour pause nukes the urgency, while the reboot cuts live voice calls used to coach marks. Power users only swim through the gauntlet once; after that they can flip a switch for a seven-day or permanent sideload window.
Who gets the scarlet letter? Any dev that won’t hand over a government ID, legal address and phone number—or pay the new registration levy—lands in the unverified bucket. Students and hobbyists can still hand out builds to 20 friends, but only through a special “limited distribution” profile that arrives in August.

The rollout map
Brazil, Indonesia, Singapore and Thailand taste the medicine first; the rest of the planet waits until 2027. For 99 % of users the Play Store bubble stays untouched—only the APK tinkerers and third-party-store faithful will feel the sandpaper.
Expect underground forums to explode with scripts promising to bypass the wait. They won’t work; the timer lives in Play Protect’s cloud, not your device clock. Google is betting that most crooks would rather abandon the platform than publish their real passport. If that gamble pays off, the price of a one-day delay will be measured in fewer drained bank accounts—and that, for once, is a trade-off even the most vocal open-android purist might stomach.
