{"id":473131,"date":"2026-06-12T04:13:19","date_gmt":"2026-06-12T04:13:19","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/473131\/"},"modified":"2026-06-12T04:13:19","modified_gmt":"2026-06-12T04:13:19","slug":"your-forgotten-apps-are-a-bigger-security-risk-than-you-think-and-googles-about-to-prove-it","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/473131\/","title":{"rendered":"Your forgotten apps are a bigger security risk than you think \u2014 and Google&#8217;s about to prove it"},"content":{"rendered":"<p>Scroll through your app drawer, and you&#8217;ll probably find a bunch of apps you forgot you installed.<\/p>\n<p>A remote control app for a gadget you don&#8217;t own anymore. Some random utility you downloaded for one specific problem and never opened again.<\/p>\n<p>The problem is that when developers abandon those apps, or Google removes them from the Play Store, they can still sit on your phone, and you&#8217;d have no idea.<\/p>\n<p><a href=\"https:\/\/www.androidpolice.com\/google-play-is-about-to-warn-you-before-apps-disappear\/\" target=\"_blank\" rel=\"nofollow noopener\">Google may soon warn users<\/a> when the forgotten apps on their phones are no longer welcome in the Play Store.<\/p>\n<p>APK teardowns show work-in-progress features. The feature may change, be delayed, or never roll out.<\/p>\n<p>                        A Play Store teardown points to a useful safety alert<\/p>\n<p>            The Play Store may revisit old installs<\/p>\n<p>        <img width=\"1650\" height=\"928\" loading=\"lazy\" decoding=\"async\" alt=\"The Google Play Store logo on a purple background\" data-img-url=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/google-play-store-logo-1.jpg\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/google-play-store-logo-1.jpg\" class=\"img-brightness-opt-out\"\/><\/p>\n<p> An APK teardown of Google Play Store version 51.4.19 <a href=\"http:\/\/www.androidauthority.com\/google-play-store-app-removal-notification-apk-teardown-3670936\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">by Android Authority<\/a> found a work-in-progress code showing the company is preparing to warn users when an installed app has been pulled. The notification reads:<\/p>\n<p>%1$s was removed from Google Play and will no longer receive updates<\/p>\n<p>%1$s and %2$d other apps were removed from Google Play and will no longer receive updates<\/p>\n<p>%1$s and %2$s were removed from Google Play and will no longer receive updates<\/p>\n<p>                        Play Protect only solves part of the issue<\/p>\n<p>            Not every problem is malware<\/p>\n<p>        <img width=\"1650\" height=\"928\" loading=\"lazy\" decoding=\"async\" alt=\"Illustration of some shields with the Google logo, padlock, password, and settings icons\" data-img-url=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/double-check-google-security-settings.png\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/double-check-google-security-settings.png\" class=\"img-brightness-opt-out\"\/><br \/>\n        Credit:\u00a0Lucas Gouveia \/ Android Police<\/p>\n<p> <a href=\"https:\/\/www.androidpolice.com\/google-play-store-play-protect-malicious-apps-report-2024\/\" target=\"_blank\" rel=\"nofollow noopener\">Google Play Protect<\/a> already scans your device and blocks apps it considers high-risk. If something is caught stealing credentials or lying about what it does, you get an aggressive push notification.<\/p>\n<p>But Play Protect is designed for harmful apps and risk cases. It isn&#8217;t really built to tell users when an old installed app has been delisted or left behind without updates.<\/p>\n<p>If a developer pulls their app because they can&#8217;t afford the server bills anymore, or Google delists an app because the developer didn&#8217;t update a privacy policy, you are in a blind spot.<\/p>\n<p>                        App neglect can become a security problem<\/p>\n<p>            Old code does not age gracefully<\/p>\n<p>        <img width=\"1650\" height=\"928\" loading=\"lazy\" decoding=\"async\" alt=\"An Android mascot on a smartphone screen, surrounded by a blue security shield icon and a floating key symbol, with a permission toggle graphic blurred in the background\" data-img-url=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/an-android-mascot-on-a-smartphone-screen-surrounded-by-a-blue-security-shield-icon-and-a-floating-ke.png\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/an-android-mascot-on-a-smartphone-screen-surrounded-by-a-blue-security-shield-icon-and-a-floating-ke.png\" class=\"img-brightness-opt-out\"\/><br \/>\n        Credit:\u00a0Lucas Gouveia\/Android Police<\/p>\n<p> Even non-malicious abandoned apps are a problem. Android keeps evolving with new permission models and privacy rules, and old code rots. What used to be harmless can become an open door to your data.<\/p>\n<p>Cybersecurity firm <a href=\"http:\/\/www.blackduck.com\/blog\/cyrc-advisory-remote-code-execution-vulnerabilities-mouse-keyboard-apps.html\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Black Duck published an advisory<\/a> about three Android remote mouse and keyboard apps with a combined two million installs on the Play Store. They found critical remote code execution vulnerabilities in all three.<\/p>\n<p>The apps were abandoned, but anyone who had already installed them was carrying around an unpatched liability with no idea that anything was wrong.<\/p>\n<p>A direct Play Store notification would have given those people the push to delete the apps.<\/p>\n<p>                        The biggest question is what happens outside the Play Store<\/p>\n<p>            Power users are on their own<\/p>\n<p>        <img width=\"1650\" height=\"928\" loading=\"lazy\" decoding=\"async\" alt=\"A close up on a prompt to install the Epic Games store via sideload on a Pixel 9 Pro.\" data-img-url=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/sideload-hero-epic-2024.jpg\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/sideload-hero-epic-2024.jpg\" class=\"img-brightness-opt-out\"\/><\/p>\n<p> There is one question mark surrounding Google&#8217;s new warning system. How will it handle <a href=\"https:\/\/www.androidpolice.com\/google-takes-its-first-real-step-against-sideloading\/\" target=\"_blank\" rel=\"nofollow noopener\">sideloaded apps<\/a> installed from outside the Google ecosystem?<\/p>\n<p>Because this feature is still in the pre-release code, we have to wait and see whether it will be strictly limited to the Play Store&#8217;s database.<\/p>\n<p>On one hand, the feature is being built into the Play Store app, suggesting it might only monitor packages pulled from its own official catalog.<\/p>\n<p>On the other hand, Google Play Protect already scans sideloaded apps for known malware and security risks and has a mechanism that analyzes third-party APKs on your device.<\/p>\n<p>Until the feature goes live, we won&#8217;t know for sure. For the average consumer, a Play Store-only restriction wouldn&#8217;t be a problem.<\/p>\n<p>But for power users who rely on the open nature of Android, it means keeping an eye out to see whether Google&#8217;s new safety net extends to all apps.<\/p>\n<p>                                                                                                                            <a href=\"https:\/\/www.androidpolice.com\/this-new-play-protect-feature-makes-little-sense\/\" rel=\"nofollow noopener\" target=\"_blank\"><br \/>\n                        <img width=\"440\" height=\"248\" loading=\"lazy\" decoding=\"async\" alt=\"Google Play\" data-img-url=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/google-play-1-ap24-hero-2.jpg\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/google-play-1-ap24-hero-2.jpg\"\/><\/p>\n<p>                    <\/a><\/p>\n<p>                    Related<\/p>\n<p>\t\t<a href=\"https:\/\/www.androidpolice.com\/this-new-play-protect-feature-makes-little-sense\/\" title=\"Google to ease sideload warnings with an option to pause Play Protect\" target=\"_blank\" rel=\"nofollow noopener\"><br \/>\n\t\t\tGoogle to ease sideload warnings with an option to pause Play Protect<br \/>\n\t\t<\/a><\/p>\n<p class=\"display-card-excerpt\">Play Protect auto-enables the next day<\/p>\n<p>                        Don&#8217;t wait for Google to clean up your phone<\/p>\n<p>Taking the burden of discovery away from the user is a big win. You shouldn&#8217;t have to read security blogs to learn that your PDF scanner from 2020 is now dead.<\/p>\n<p>But this warning system is currently a string of code buried in a Play Store teardown. It could be months before the feature reaches your phone.<\/p>\n<p>You don&#8217;t have to wait for Google to tap you on the shoulder to <a href=\"https:\/\/www.androidpolice.com\/ways-delete-unused-apps-android\/\" target=\"_blank\" rel=\"nofollow noopener\">start cleaning your device<\/a>. Open your app drawer, question the apps you forgot, and uninstall anything you no longer use or recognize.<\/p>\n<p>It&#8217;s also a good excuse to check your app permissions. Not every app on your phone needs access to your location, contacts, files, microphone, or camera.<\/p>\n","protected":false},"excerpt":{"rendered":"Scroll through your app drawer, and you&#8217;ll probably find a bunch of apps you forgot you installed. A&hellip;\n","protected":false},"author":2,"featured_media":473132,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[342,111,139,69,145],"class_list":["post-473131","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-mobile","tag-new-zealand","tag-newzealand","tag-nz","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/473131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=473131"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/473131\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/473132"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=473131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=473131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=473131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}