01
Capture the current baseline
Before downloading, open Android app information for the working installation. Record non-sensitive details that can be compared later, including the installed package identifier where available.
- Installed app name and package identifier
- Source used for the current install
- Current permissions
- A dated screenshot with private data masked
02
Review the proposed release
Read any change explanation and separate functional notes from promotion. Missing notes do not prove a file is wrong, but they are a reason to examine the source and identity more carefully.
- Confirm the final destination domain.
- Compare package and signing details.
- Review new permission requests in context.
03
Check after installation
Open the app without making a transaction or entering sensitive data first. Confirm that familiar navigation and account routes remain coherent, then review Android permissions again.
- Look for an unexpected second icon.
- Check for unfamiliar browser redirects.
- Stop if identity details changed without explanation.