Google plans to restrict APK sideloading from 2026, making unofficial app installs more difficult

Google is reinforcing controls over APK sideloading, introducing restrictions in 2026 that could limit users’ ability to install apps from unofficial sources, raising concerns over security and access to region-locked or older apps.

Installing APK files on Android still gives users access to software they cannot get through Google Play, including region-locked apps, older releases and builds with extra features. But the process is becoming harder to rely on. According to “Kod Durova”, Google is continuing to tighten controls around sideloading, with further restrictions due from 30 September 2026 on certified devices in Brazil, Indonesia, Singapore and Thailand, and broader changes planned for 2027 and beyond.

APK, or Android Package Kit, is the standard installation format for Android applications. The file contains the app’s code, resources and metadata, much as an EXE file does on Windows. Installing it outside the Play Store is known as sideloading. Android blocks that path by default because unofficial sources are a common route for malware. Kaspersky warned in 2026 that Android users remain exposed to a growing threat landscape, including trojans and other attacks that can slip past built-in protections when apps are installed from outside official stores.

The practical method has not changed much on recent versions of Android. Since Android 8.0, permission to install unknown apps is granted to a specific app, such as a browser or file manager, rather than to the whole device. Users must open the relevant settings area, allow that app to install unknown applications, then return to the permission once the APK has been installed. Security specialists recommend limiting that permission to the shortest possible time and turning it off again straight away.

Safety depends heavily on where the file comes from. The article from “Kod Durova” recommends official developer sites, GitHub Releases, F-Droid and APKMirror, and warns against Telegram channels, Discord links and other unverified sources. It also advises checking APKs with VirusTotal before installation, comparing file sizes with official releases and avoiding modified builds, which may contain altered code or hidden permissions. Malwarebytes has similarly argued that Google’s new “Advanced Flow” is intended to make sideloading safer by adding identity checks for developers.

Google’s direction of travel is clear: sideloading will not disappear, but it will become less straightforward. CNX Software and Android Central reported that from September 2026, certified Android devices in the first rollout countries will require developer verification before apps from unregistered developers can be installed in the normal way. That makes the old assumption that any APK can simply be tapped and installed increasingly unreliable. For most users, the remaining risks are familiar and serious: data theft, remote control of the device, financial loss and trojan infection.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.