What Is Sideloading on Android? Risks, Safeguards and Google's New Verification Rules
Sideloading means installing an Android app from somewhere other than the official app store, usually by opening an APK file you downloaded or copied. It is built into Android and has legitimate uses, but it also skips the checks that Google Play applies, so the safety work falls to you.
- Sideloading means installing an app from outside a store, such as from an APK file; it skips the store's review.
- Android controls it per source app[1], and Play Protect can still scan what you install[3].
- The main risks are repackaged and fake apps, missing updates, and installs that bypass age ratings and parental approval.
- Safer sideloading means a trusted source, a verified file, a check of its permissions, and turning the install permission off afterwards.
What sideloading is
Most people install apps from Google Play, or from a manufacturer's store such as the Samsung Galaxy Store. Sideloading is any install that does not go through a store: tapping an APK file in your downloads, installing from a third-party app store, or pushing an app from a computer with the Android Debug Bridge.
How Android controls it
- Per-app permission. Since Android 8.0 (API level 26), installing from an unknown source is controlled per source app rather than by one global switch, and apps check it with
canRequestPackageInstalls().[1] Allowing your browser to install files does not allow every app to. - Restricted settings. Since Android 13, an app that was itself sideloaded is blocked from enabling sensitive access such as accessibility services until you explicitly allow it, as reported ahead of the Android 13 release.[2]
- Play Protect. Google's Play Protect can scan apps on your device, including ones that did not come from Google Play, and warn about harmful ones. Google's help page also notes it may ask you to send unknown apps installed from outside Google Play to Google for analysis.[3]
Why people sideload
- An app is not available in their country or on their device
- Installing a beta or a build direct from a developer
- Using open-source app stores
- Company-managed apps that are not published publicly
- Developers testing their own builds
The risks
| Risk | What can go wrong |
|---|---|
| No store review | Nobody has screened the file for malware or policy violations before you install it. |
| Repackaged apps | Attackers take a real app, add malicious code, and redistribute it under the same name. |
| Fake apps | Clones of popular apps and games carry adware or data theft. |
| No automatic updates | Apps from outside a store may never get security fixes. |
| Bypassed age and approval controls | An app installed from a file never passes through the store's age rating or a parent's approval flow. |
How to sideload more safely
- Use the developer's own site or a reputable open-source store. Avoid random "free APK" mirrors.
- Verify the file. Compare the SHA-256 of the file or the signing certificate fingerprint with what the developer publishes.
- Inspect it before installing. Check the declared permissions and exported components. Our APK analysis guide shows how, or upload it to the APK analyzer.
- Grant "Install unknown apps" only to the one app you use, and turn it off afterwards.
- Keep Play Protect on.
- Be skeptical of anything asking for accessibility access right after install. See our accessibility guide.
Google's developer verification plan
Google has announced that Android will begin checking that apps come from verified developers. According to the Android developer verification page,[4] protections begin on September 30, 2026 for users installing apps from participating stores in Brazil, Indonesia, Singapore and Thailand on certified devices running Android 7 or later, and verification will expand globally in 2027. Google has also described an advanced flow so power users can still install apps from unverified developers.
Rules like this are still rolling out and may change. Check the official page for current details rather than relying on a summary.
What it means for parents
If a child can install an APK file, they can add an app that never passed a store's age rating. A parental-control app helps by limiting what runs, and device settings can keep "Install unknown apps" turned off. Talk through the "why", too: a kid who understands that fake game clones steal accounts is safer than one who simply meets a block.
Frequently asked questions
Is sideloading safe?
It can be, if the file comes from the developer or a trusted source and you verify it first. It is riskier than Google Play because no store has screened the app.
Is sideloading legal?
Installing apps on a device you own is generally legal. What matters is whether the software itself is lawful to use and distribute, so avoid pirated apps.
How do I turn off sideloading on Android?
Open Settings, find "Install unknown apps" (often under Apps or Security), and make sure no app has the permission. Apps are denied by default on modern Android.
Does Play Protect scan sideloaded apps?
Play Protect can scan apps on your device, including ones from outside Google Play, and warn you about harmful ones. It is a safety net, not a guarantee.
What is an APK file?
An APK is Android's app package format, a ZIP archive that holds an app's code, resources, manifest and signature. Opening one installs the app, which is how sideloading works.
What is the difference between sideloading and rooting?
Sideloading installs an app from outside a store. Rooting gives apps superuser access to the whole system. You can sideload without rooting, and most people who sideload do.
How do I know if an APK source is trustworthy?
Prefer the app developer's own website or a reputable open-source store, and compare the file's signing certificate or checksum with what the developer publishes. Avoid anonymous "free APK" mirrors.
Will Google block sideloading completely?
Not according to the developer verification page, which describes an advanced flow so power users can still install apps from unverified developers. Rules are still rolling out, so check the official page for updates.
Can sideloaded apps update themselves?
Not automatically through Google Play. Some apps include their own updater and some stores handle updates, but many sideloaded apps never receive security fixes unless you update them by hand.
- Behavior changes: Android 8.0 (API level 26) — Android Developers — changes to installing unknown apps from unknown sources and canRequestPackageInstalls().
- Android 13 Restricted setting feature blocks sideloaded apps — Chrome Unboxed (July 8, 2022) — independent reporting on the Android 13 restricted-setting change; secondary source.
- Google Play Protect — Google Play Help — scanning apps and sending unknown apps to Google.
- Android developer verification — Android Developers — rollout dates, regions and the advanced flow for power users.