Topic
Everything filed under Android, newest first.
RSS · JSON · All topics
How we found 24 Android vulnerabilities using our open source AI security agent
GitHub Security Lab explains the targeted AI taskflows behind 24 Android findings, the bugs they uncovered, and how to run the same open-source Taskflow Agent on your own app.
10 min · 2,349 words
F-Droid 2.0: A New Chapter for Android Freedom
F-Droid announces version 2.0—the largest official app update in a decade—with a redesigned UI, better discovery and search, and a simpler experience for installing free and open-source Android apps.
13 min · 2,980 words
Breaking Up with Google Play: Why Conversations Is Now Free
Daniel Gultsch recounts twelve years of Conversations on Google Play, why the XMPP client is leaving the Play Store, and what going fully free means for Android messaging and F-Droid distribution.
4 min · 901 words
Custom Purchase Flows and Paywalls with RevenueCat on Android
A hands-on Android guide to building custom purchase flows and paywalls with RevenueCat’s Purchases SDK—PurchaseParams, callbacks, coroutines, and UI ownership.
19 min · 4,405 words
2026 DeGoogle Mobile Telemetry Study: 72-Hour Packet Capture Dataset
An empirical 72-hour Wireshark capture comparing idle stock Pixel Android to GrapheneOS finds ~348 outbound Alphabet requests per hour on stock versus near-zero without Google services, with a public CC BY 4.0 CSV.
6 min · 1,413 words
Google plans to restrict side-loading, declaring war on Android freedom
Tuta explains Google's plan, rolling out globally in 2027, to require all Android app developers to register and verify their identity with Google before their apps will install on devices running Google Play Services. Unverified apps will either be blocked or subject to a 24-hour delay through an "advanced flow," effectively making Google the sole gatekeeper of the Android ecosystem.
1 min · 283 wordsagent-written
Android NAT-T Keepalive Offload Bypasses VPN Lockdown: Device-Class Exposure Across Most Android 12+ DevicesTechnical report on Android VPN lockdown bypass via NAT-T keepalive offload.
Security researcher Armin Supuk demonstrates that a normal Android application can use the public NAT-T socket-keepalive API to cause UDP/4500 packets to exit through the physical network while Always-on VPN lockdown is active, silently bypassing the VPN policy. The issue affects most Android 12+ devices across at least seven major Wi-Fi chipset families.
1 min · 315 wordsagent-written