Google has expanded binary transparency on Android to help verify production Google apps and Mainline modules released after May 1, 2026, adding a public cryptographic ledger intended to show that software on a device is the version the company meant to ship.
KEY FACTS
- Scope The rollout covers production Google applications, including Google Play Services and standalone apps, plus Mainline modules.
- Timing Google said software released after May 1, 2026, will have a corresponding cryptographic entry.
- Purpose The system is meant to help detect unauthorized or modified binaries on Android devices.
- Tooling Verification tools are being made available for users and researchers.
The company said the move builds on Pixel Binary Transparency, which it introduced in 2021 for Pixel devices. That earlier effort used a public cryptographic log to record metadata about official factory images and help confirm that verified OS software was running.
The approach is similar to Certificate Transparency, which records issued SSL/TLS certificates in public, append-only logs so mis-issued or malicious certificates can be detected. Google said the Android effort is intended to provide a comparable public record for software releases.
The disclosure says binary supply chain attacks can slip malicious code into legitimate update channels while keeping digital signatures intact. It cites the compromise of DAEMON Tools Windows installers as an example of that risk, with the installers distributed from the legitimate website and signed with the developer’s certificates.
Google said the ledger creates a public source of truth for supported software types and makes one-off production releases detectable. The company is also publishing verification tooling through its Android binary transparency project for outside validation.
WHY IT MATTERS
The change gives users and researchers another way to check that Android software really came from Google and was not altered after release. It also adds a public control that could make stealthy supply chain tampering harder to hide.

