AI News Feed
Market watch
Policy & Regulation

Russia Warns Google’s Android Developer Checks Could Limit Local Apps; Security Firm Reports 11 Flaws

Russia fears Google Android checks may limit its apps; Positive Technologies says 11 flaws hit Google, Apple.

Google has not announced any ban on Russian developers, but the ministry is assessing the dangers and preparing proposals with industry groups to limit possible damage. The ministry objects to the technical framework because it could let Google influence which software from Russian programmers reaches users. The scheme requires authors to prove who they are and register each application, including programs obtained through independent shops or installed from standalone package files.

Google bought the startup that created Android in 2005, and the system rests on freely available code that any mobile phone maker is allowed to adopt. Yet many devices still depend on Google’s cloud services and must gain approval from the firm, giving it substantial sway over huge numbers of phones. Alternative app marketplaces in Russia cover only part of what users want, so any extra installation hurdle would fall on people with few real substitutes.

Under the scheme, any user installing software from developers lacking verification must change phone settings and then confirm with a fingerprint or lock passcode. The user must then restart the phone, wait 24 hours, and reopen the configuration menu to continue with the installation. Finally, the user chooses whether the exemption lasts seven days or has no end date, so one unofficial program will take over one day to install.

Google’s rollout of the checks will commence on September 30, 2026 in Thailand, Singapore, Brazil and Indonesia. Although the company has not listed Russia among countries facing any restriction aimed at its programmers, it plans to expand the checks to more countries next year. Therefore, the Russian government is already anticipating that it will be on the list sooner or later. Google explains that the checks are a safeguard against harmful programs, though that claim still awaits proof from concrete results from the first round of checks.

TechRadar noted that the discussion comes nearly 56 months after the war in Ukraine began. While Google’s security rationale remains plausible, a system verifying developers and controlling external installations could provide a mechanism that other governments may scrutinize. For Russian users the practical risk is delay rather than disappearance, since a determined user could still install unverified software once the waiting period ends. Whether the 2027 expansion includes Russia remains unknown, and until Google says so the ministry is answering a hypothetical restriction with real preparation. Developers already removed from marketplaces have the most to lose if Google’s verification system prevents users from installing their applications.

Separately, Russian cybersecurity firm Positive Technologies, which is under American sanctions, claimed it discovered 11 security flaws affecting Android and Apple devices. The company gave the findings to Russian news agency TASS, TechRadar reported. Nine of the flaws affected Apple devices and software, while two affected Android, including Pixel phones, and were reportedly rated high severity.

The first Android flaw let attackers use a crafted NFC tag to fetch, set up, and run an app while the owner approved nothing. The second allowed an app already on the phone to alter network settings, including joining a chosen Wi-Fi network, without any extra permissions, and also let the app add a certificate or adjust proxy parameters, and neither action required the phone owner to confirm anything. Google resolved both Android flaws in its September 2026 patches, so devices which have installed those patches should no longer face either problem. Positive Technologies describes the tag flaw as especially hazardous since holding a phone near the tag suffices to trigger it. There was no mention of specific Android versions or Pixel models that were vulnerable, so the number of exposed devices remains unknown.

According to TASS, the nine Apple flaws covered higher access rights, privacy exposure, and weakened data safeguards. One macOS flaw allowed a hostile app to obtain the highest level of control over the computer, and another exposed information the system normally protects. The keys used for access could be deleted without the user approving the action. Another flaw was found inside the kernel of the operating system and could cause a device to fail or corrupt data held in memory. Apple has released patches for the flaws, although the company did not say which operating system versions carry the fix. Devices that never received an update stay exposed to every flaw the firm described, whatever patches the vendors have issued. Owners of older phones and computers that no longer receive vendor updates face the most uncertainty, because a fix never reaches them. Android owners should check their software version in system settings to confirm the September 2026 patches arrived on their devices. Neither Apple nor Google acknowledged the Positive Technologies report, but they both released patches fixing these flaws, which TechRadar said implies that the report is legitimate.