The app ID is com.google.android.verifier, which I assume will be used for the upcoming developer verification program for installing 3rd party apps.

Starting September 30, developers (signing authors) need to be verified from Google to distribute apps in the following app stores:

  • Google Play Store
  • Honor App Market
  • OPPO App Market
  • Samsung Galaxy Store
  • Transsion Palm Store
  • vivo V-Appstore and
  • Xiaomi GetApps

only in the countries of Brazil, Indonesia, Singapore and Thailand.

F-Droid is not included for this time.

It is planned to be rolled out globally across all markets/app stores by January of 2027.

Relevant sources:
https://developer.android.com/developer-verification/guides
https://keepandroidopen.org/

I used App Manager (io.github.muntashirakon.AppManager) for the screenshot; you can use your regular ‘Installed Apps’/‘Apps’ menu to see if it’s been rolled out automatically for you as well.

edit: First link was originally a typo, my bad. Fixed it.

  • Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    14
    ·
    edit-2
    10 hours ago

    My kids’ phones (Pinwheel-managed Moto G Play models) attempted to install this in the background as well. I only found out about it because I got an app request from the devices; the kids had zero knowledge of it.

    I blocked the installation.

  • Anti_Iridium@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    10 hours ago

    When it rolled out, it removed my root as well. I guess I may be jumping ship to lineageos soon. I like root features too much.

    • Turret3857@infosec.pub
      link
      fedilink
      English
      arrow-up
      15
      ·
      edit-2
      14 hours ago

      At this time it is currently better to go with a custom Android ROM. Linux phones are currently have almost 0 security. I say almost 0 because postmarketos does support LUKS encryption, but only on some devices, and pmos uses an “upstream kernel” update model for devices, so a lot of the drivers for supported phones are not fully complete.

      None of them have sandboxing, or measured boot, and excluding postmarketos, none of them get driver level security updates either.

  • Appoxo@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    57
    arrow-down
    1
    ·
    21 hours ago

    F-Droid is not included for this time.

    How-To:

    • Open Developer Options and select Apps from unverified developers.
    • Turn on Allow apps from unverified developers.
    • Authenticate using your screen lock.
    • Confirm that nobody is pressuring you to change the setting.
    • Restart your phone and wait 24 hours.
    • Return to the setting and choose whether to allow apps from unverified developers for seven days or indefinitely.

    Source:
    https://www.androidauthority.com/google-android-advanced-flow-sideloading-rollout-begins-3700073/
    https://www.pocket-lint.com/android-new-sideloading-option/

    • d-RLY?@lemmy.ml
      link
      fedilink
      English
      arrow-up
      7
      ·
      7 hours ago

      After going through both my Galaxy 24U and Pixel Tablet initially, I wasn’t seeing the option (was looking for the old “Install from unknown sources” which is in a different location (and per app toggles). I went back and manually disabled and enabled the “Android Developer Verifier” app and then saw the option for “Apps from unverified developers” show up. Then was able to follow the steps (very glad you provided that second source which is what led me to what I did).

      So I guess if you don’t see it. First search in your apps that the verifier app is present. If it is, then go into the app info for it and toggle disable and then enable. Willing to accept that maybe I was just blind to it due to the old way of sideloading that made me miss it in Developer Options. But for sure saw it after the toggles. Now I just need to remember to go back tomorrow to set the “indefinitely” option. Curious if this will allow Play Protect to not try to yeet apps if PP is turned back on. I had to turn it off a couple months ago because it kept flagging SyncThing-Fork installed from F-Droid trying to trick me into uninstalling it (which was weird that was the only app it freaked out about out of all the third-party store and Obtainium apps).

    • zout@fedia.io
      link
      fedilink
      arrow-up
      51
      ·
      20 hours ago

      That’s some pretty big hurdles to be honest, just a reminder of how sketchy Google is these days.

      • Appoxo@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        2
        ·
        19 hours ago

        Less issue for me than Apple lol.

        You can always (for now) go to LineageOS or GrapheneOS ¯\_(ツ)_/¯

        • Zedstrian@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          27
          arrow-down
          1
          ·
          edit-2
          8 hours ago

          Every shift away from open Android that users accept emboldens Google to lock it down further.

          • Appoxo@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            9
            arrow-down
            2
            ·
            18 hours ago

            Switching from Android to Apple is really smart lol.
            Why would you even switch from a pretty much open system to a fully closed one (even with the things the EU forces Apple to do)?
            (This questions excludes Linux OSs on smartphones)

            • Zedstrian@sopuli.xyz
              link
              fedilink
              English
              arrow-up
              7
              ·
              18 hours ago

              Apple is of course still far worse, but users shouldn’t be accepting Google’s changes to Android without complaint.

        • zout@fedia.io
          link
          fedilink
          arrow-up
          7
          arrow-down
          1
          ·
          19 hours ago

          Not if you want your banking app to work, or some other apps that require you to have the “certified” os on your phone. If I have to stop using these apps, I might as well go back to a dumbphone.

          • Lka1988@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            10 hours ago

            Not if you want your banking app to work, or some other apps that require you to have the “certified” os on your phone. If I have to stop using these apps, I might as well go back to a dumbphone.

            I would rather stop using apps that require this bullshit than give up the literal pocket computer that’s powerful enough to do damn near whatever I want with it. I make my phone my bitch and I intend to keep it that way.

            Banking apps that require this aren’t worthy of being installed. Just use their website. Banks still have websites.

            • zout@fedia.io
              link
              fedilink
              arrow-up
              1
              ·
              1 hour ago

              I would rather stop using apps that require this bullshit

              Yeah, one of these apps is needed to log on into government websites to do my taxes and communicate with different agencies. It is possible to do without, but not practical.

            • Diurnambule@jlai.lu
              link
              fedilink
              English
              arrow-up
              1
              ·
              10 hours ago

              They ask to enter a pin on the application to unlock the web site. I may have to leave my bank…

          • Jakeroxs@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            6
            ·
            18 hours ago

            Web browsers exist still, though some particularly shitty sites don’t even have a mobile web view these days.

          • Turret3857@infosec.pub
            link
            fedilink
            English
            arrow-up
            2
            ·
            16 hours ago

            My bank currently works but in the past it hasnt and the website worked just fine for the period of time the app didnt work.

          • Vogi@piefed.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            15 hours ago

            My Bank works even without microG or some other Google supplement. It does show a warning on the initial boot that it might not, but it does. They also do not require to have the app, but its still nice to have.

            • Lka1988@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              edit-2
              10 hours ago

              You don’t “use Magisk” to do that. Magisk only provides a path to do so.

              What modules are you using to achieve this?

  • onionsinmypores@sh.itjust.worksOP
    link
    fedilink
    English
    arrow-up
    72
    arrow-down
    1
    ·
    21 hours ago

    Update: Interestingly, since it is still classed as a User app, I can uninstall it myself without any special perms. The installation source is shown as Google Play Store, and you can manually find the app on the store.

    Here’s a screenshot of that - though it has no ratings, reviews, options to review etc. that you would expect from ordinary or even other Google produced apps.

    • zout@fedia.io
      link
      fedilink
      arrow-up
      20
      ·
      20 hours ago

      I can find it there, but only uninstall updates. Guess it’s ADB time.

      • BeatTakeshi@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        14 hours ago

        Same for me, I can only uninstall the updates, and I can’t tell the play store to not update it automatically, so it will obviously do this. I’m eyeing at fairphone, or graphene, or /e/os, or Jolla, or iodé, or calyx, or lineage, or pinephone a bit more everyday

  • REDACTED@infosec.pub
    link
    fedilink
    English
    arrow-up
    13
    ·
    edit-2
    15 hours ago

    Weird, I could uninstall it (and the key verifier one too), and so I did. Yeah, this is definitely not going to come back to bite me in the ass

    EDIT: OnePlus Open, I haven’t unlocked bootloader or rooted it.

    • lost_faith@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      ·
      17 hours ago

      Been using my pixel 6, according to the app list it has been “used since Aug 13” I cannot archive(greyed out), disable says (get this) “It came preinstalled on my device” funny since I’ve been using this device for years and by its own account was just installed aug 13

      • Turret3857@infosec.pub
        link
        fedilink
        English
        arrow-up
        6
        ·
        16 hours ago

        You can probably get rid of it by installing GrapheneOS, CalyxOS, iodéOS, or LineageOS, unless youre in the US and bought the phone from Verizon

            • Lka1988@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              3
              ·
              10 hours ago

              Bummer 🫤

              Wasn’t the entire point of custom ROMs to avoid this whole situation to begin with? Doesn’t make sense for a custom ROM to drop support once official support has ended, it kinda defeats the purpose of keeping an older device…

              • Turret3857@infosec.pub
                link
                fedilink
                English
                arrow-up
                3
                ·
                9 hours ago

                The security model of GrapheneOS and CalyxOS are similar on this specific issue. They drop support after OEM support has ended because the proprietary drivers that are borrowed from the official ROM stop being updated. It introduces an unpatchable security hole unless someone can reverse engineer all the proprietary drivers and keep updating them with security fixes, and even then, hardware security flaws may eventually surface.

                LineageOS and iodéOS are good for keeping older devices working as long as you are okay with a looser threat model (not having those hardware level security updates, and not having the extra features provided by Graphene or Calyx)

                postmarketos is a Linux distro aimed at reverse engineering those drivers to allow supported phones to live even longer. However, the team doesnt recommend ANY devices for daily driving. The OnePlus 6T and Pixel 3 are recommended for people who want a tolerable experience but they are not perfect. The Pixel 6 series was recently supported, but Im not even sure if they have graphics drivers working yet. (not to mention, pmos has no security features outside of LUKS encryption. No measured boot, no sandboxing, no fine grain permission control etc)

    • untorquer@quokk.au
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      20 hours ago

      Goto “app details” at the bottom of the settings page for the app. Then select “uninstall updates” should no longer appear in app list.

      • PointlessLifePersonified@slrpnk.net
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        18 hours ago

        “App details” is greyed out for me. Pixel 7 Pro.

        Edit: never mind - it was because I had the Play Store disabled. Not that it’ll mean much, but I flagged the app as inappropriate while I was there.

        Edit 2: Wow, they’re paying for fake reviews that are blatantly a bad joke.

  • Vogi@piefed.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    15 hours ago

    What happens if you try to install an unverified apk now? Like is there a message or something? Does it go away after just uninstalling the developer verifier?

    • Psythik@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      15 hours ago

      This app also got silently installed on my device, but I just updated YouTube Morphe and there was no issue. So for now the app doesn’t appear to do anything. I disabled it and will be uninstalling with ADB soon.

      • Vogi@piefed.social
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        15 hours ago

        Ah okey, thanks for the info :)
        Better hope they do not merge it into Google Play Services then and that I didn’t just jinx that to happen…

  • atro_city@fedia.io
    link
    fedilink
    arrow-up
    16
    arrow-down
    1
    ·
    21 hours ago

    No idea where you are nor which phone you have, but maybe it’s time to install an Android alternative OS (not sure what to call it) like GrapheneOS, LineageOS, or eOS. From what I understand they don’t allow this kind of shit.

    • I Cast Fist@programming.dev
      link
      fedilink
      English
      arrow-up
      28
      arrow-down
      1
      ·
      21 hours ago

      Easier said than done, especially as there are more models that don’t have any sort of support for those OSs than models that do. Not to mention the hassle to even enable the option to flash it and risk of bricking. Worse, banking apps may refuse to work.

      Google and the OEMs never wanted you to own your phone and they are mostly winning on that front.

      • FunnySalt@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        6
        ·
        18 hours ago

        Easier said than done, especially as there are more models that don’t have any sort of support for those OSs than models that do.

        This is a big hurdle. I had to buy a different phone to install a custom ROM. I bought it used, but even so still fairly expensive. And an extra cost can be a limiting factor too.

        Not to mention the hassle to even enable the option to flash it and risk of bricking

        GrapheneOS has a webUSB installer that is very easy to use. I would argue it eliminates the hassle. Bricking is still a risk.

        Worse, banking apps may refuse to work.

        I don’t use banking apps on my phone. I don’t like having anything installed that has access to money. I just access my financial institutions via their website. But I acknowledge they may fill some need others have that I do not. And that not everyone has access to a computer to access websites , and I can see banks trying to force app use when accessing from a mobile browser.

      • HerbGrower@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        16 hours ago

        Could go back to a flip phone tbh. Only got a FF4 a few months ago and put calyx on it, used a flip phone before that for a few years.

          • HerbGrower@slrpnk.net
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            15 hours ago

            Its only to receive calls from people and employers who still use phone/SMS as a contact method.

            Anything important can be done on a Linux PC. So then the question is how portable of a Linux PC can I comfortably get.

      • benjirenji@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        15 hours ago

        Just buy a phone that comes preinstalled without Google.

        My banking apps all work. Some of the shittier apps that force you to watch ads break though.

  • Willie169@infosec.pub
    link
    fedilink
    English
    arrow-up
    2
    ·
    14 hours ago

    I block system update immediately when I heard this. Though I could use Shizuku, who knows when they will block loop back ADB. And the recent CVE-2026-43499 exploits are another reason to keep me holding my kernel version. BTW, I now have 0 app are my phone that receives update from Google Play or those OEMs stores now. Some still use APKPure over Obtainium or Aurora Store, but most are FOSS.