Google reported that its 2025 enforcement and review efforts blocked over 1.75 million policy-violating app submissions from being published on Google Play and resulted in bans of more than 80,000 developer accounts tied to harmful behavior. Google attributed these outcomes to expanded AI-powered, multi-layered defenses, including developer verification, mandatory pre-review checks, and testing requirements intended to raise the barrier for malicious or non-compliant apps and reduce user harm such as malware, financial fraud, hidden subscriptions, and privacy-invasive behavior.
Google also said it prevented over 255,000 apps from obtaining excessive access to sensitive user data and that Google Play runs 10,000+ safety checks as part of its protections, with detection strengthened by integrating newer generative AI models to help reviewers identify evolving malicious patterns. Additional ecosystem integrity measures cited include blocking 160 million suspicious/inauthentic ratings and identifying large volumes of malicious sideloaded apps via Play Protect, which Google said scans hundreds of billions of apps daily and expanded “enhanced fraud protection” coverage broadly across Android devices, blocking large numbers of risky installation attempts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On February 19, 2026, Google publicly released its annual review summarizing 2025 security actions across Google Play and Android, including AI-driven app review, anti-fraud measures, and Play Protect statistics. Multiple outlets then reported the same findings from the published review.
Google said Android 16 introduced built-in mitigations against tapjacking and hidden-window attacks that can trigger fraudulent taps or expose sensitive data. The protections were highlighted as part of the platform's 2025 security improvements.
During 2025, Google introduced in-call scam protections designed to stop social-engineering attempts that try to convince users to disable Play Protect while on phone calls. The feature was presented as a defense against fraud and sideloading-based attacks.
In 2025, Google expanded Play Protect's enhanced fraud protection to 185 markets covering 2.8 billion Android devices. The company said the feature blocked 266 million installation attempts involving 872,000 unique risky apps requesting sensitive permissions.
Across 2025, Google Play Protect scanned more than 350 billion apps daily and identified over 27 million new malicious apps, primarily from outside Google Play. Google said this reflected the growing importance of defending against sideloaded and off-store threats.
In 2025, Google reported blocking more than 255,000 apps from obtaining excessive access to sensitive user data and stopping 160 million spam or manipulated ratings and reviews, including mitigation of review bombing. These actions were part of broader privacy and anti-abuse enforcement on Google Play.
During 2025, Google said it prevented more than 1.75 million policy-violating apps from being published on Google Play and banned over 80,000 developer accounts associated with harmful activity. Google attributed the results to its layered review and enforcement systems.
Throughout 2025, Google expanded app ecosystem protections including developer verification, mandatory pre-review checks, more than 10,000 safety checks per app, generative-AI-assisted app review, and broader post-publication monitoring. It also rolled out Play Integrity API enhancements, device recall beta, and other developer-facing security tools to harden the ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcetechrepublic.com
Open sourcehelpnetsecurity.com
Open sourcesecurity.googleblog.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourcesecurity.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.