Google Play will require Android apps and games to meet new technical-quality thresholds for dynamic memory use, bitmap memory use, and DEX code optimization beginning in February 2027. Apps that fail to comply may face reduced Play Store visibility and publishing restrictions. Developers can use Play Console and Android vitals to identify memory consumption, out-of-memory terminations, and code-optimization metadata; Google recommends enabling R8 code and resource optimization in tested release builds, maintaining appropriate keep rules, and retracing obfuscated crash reports.
Starting in April 2027, Android apps with sign-in functionality must implement the Restore Credentials API to preserve account access during migration to a new Android device; games are initially exempt. The feature creates a restore key after authentication on the previous device, stores it through Android Backup when eligible, and restores it via cloud backup or USB device-to-device transfer, supporting passkeys, passwords, and Sign in with Google. It silently restores one account per app on mobile devices, reducing migration-related sign-in friction.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Google Play introduced Zero-Tap Sign-In for apps supporting user sign-in, requiring use of Android's Restore Credentials API to restore sign-in state when a user migrates to a new Android device. Games are initially exempt from this requirement.
Google Play added Play Console and Android vitals metrics for dynamic and bitmap memory consumption, a filter for memory-pressure-related crashes and ANRs, and DEX optimization insights for newly uploaded app bundles that provide optimization metadata.
Google Play introduced requirements covering dynamic memory use, bitmap memory use, and DEX optimization. It said apps and games that do not meet the planned thresholds could face reduced Play Store visibility and publishing capabilities when enforcement begins.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
developer.android.com
Open sourcedeveloper.android.com
Open sourcesupport.google.com
Open sourceandroid-developers.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.