01
Start with the source
Record the exact page and domain that supplied the update. Words such as latest or official inside a filename are only labels and do not establish ownership.
- Write down the full download URL.
- Compare it with the source used for the current installation.
- Avoid shortened or forwarded links when the destination is unclear.
02
Compare app identity
The visible name and icon are easy to reproduce. Where possible, compare the Android package identifier, signing information and requested permissions with the installed app.
- Keep a screenshot of the current app details.
- Stop if an alleged update installs as a second app.
- Question unrelated high-risk permission requests.
03
Protect recovery access
Confirm how the account can be recovered before uninstalling or clearing data. Save a masked account identifier and verified support route, but never store a password or one-time code in a screenshot.
- Check that recovery details are current.
- Retain the working app until comparison is complete.
- Open the new build before entering sensitive information.