Security
11 post(s)
-
Google outlines Android’s 2026 security and privacy roadmap (banking scam calls, threat detection, theft protections)
Google’s Android Security and Privacy team previews 2026 platform protections: verified financial calls to stop spoofed bank scams, expanded on-device threat detection, tighter Advanced Protection, and stronger device theft defenses.
-
Google Play’s ‘safer apps’ push: more pre-checks, more guidance, and stronger signing
Google shared a 2026 look-ahead for making it easier to publish safer apps, including earlier policy issue detection and support for post-quantum cryptography in Play App Signing.
-
Apple releases: iOS 26.4.2 + iOS 18.7.8 (notifications database fix)
Apple’s April 22 releases (iOS 26.4.2 and iOS 18.7.8) are a reminder that platform ‘bugfix’ updates can have direct privacy implications. In this case, it appears to close a hole where deleted notifications could persist in the on-device notification database.
-
EFF: push notifications can leak more than you think (lock screen, cloud routing, device databases)
EFF breaks down two privacy leak points for push notifications: what platforms can see in transit (content/metadata), and what can persist on-device (including recovered ‘deleted’ notifications). For app teams, the takeaway is simple: treat notifications as a public surface and design for minimised content.
-
Apple fixed a bug where deleted notifications could be retained on-device (iOS 26.4.2)
A credited summary of Apple’s April 22, 2026 security note for iOS 26.4.2: notifications marked for deletion could be unexpectedly retained on the device. Practical takeaway for app teams: treat notifications as a privacy and trust surface, and keep lock screen content minimal.
-
TechCrunch: Apple fixes iPhone bug that retained ‘deleted’ notification content
A credited summary of TechCrunch’s April 2026 report: iOS cached notification content in a way that could retain messages marked for deletion. Apple shipped a fix, which is a good reminder for app teams that lock-screen copy is part of your privacy model.
-
EFF: Push notifications can betray your privacy (and what to do about it)
EFF’s practical point is simple: notifications leak in two places, in transit (Apple/Google push infrastructure) and at rest (what your OS stores locally). Their advice is to reduce preview content, tighten per-app and OS-wide settings, and treat notification copy like sensitive data.
-
Android developer verification is rolling out to all developers (Play Console + the new Android Developer Console)
Google is expanding developer verification and app registration ahead of user-facing install protections later this year. Here’s what changes, when, and what to do now if you ship outside Play.
-
Android developer verification is becoming an on-device install check (via ‘Android Developer Verifier’)
Google’s new ‘Android Developer Verifier’ system service will check whether apps are registered to verified developers, with end-user protections starting in select countries in late 2026.
-
Android’s new ‘advanced flow’ for installing unverified apps: the 24-hour wait is the point
Google detailed an ‘advanced flow’ that lets power users sideload apps from unverified developers, but adds friction (developer mode, restart, re-auth, and a one-day waiting period) to break coercive scam patterns.
-
Google Play’s 2025 safety numbers: 1.75M blocked apps, 80k banned dev accounts, and ‘policy-by-default’ tooling
A credited summary of Google Play ecosystem safety reporting: how pre-review checks, developer verification, AI-assisted review, and integrity signals are becoming part of shipping, not just compliance.