Fortnite's release on Android is not security-friendly
It's finally here! One of this year's most successful game Fortnite is finally available for Android devices since August 9th. This has been wished for by many Android gamers but this dream comes with the following caveats:
- Device exclusivity - For the first 3 days this game can be installed only on Samsung devices.
- No Play store - This device is not available on the official Google Play store, it has to be downloaded from Samsung Galaxy Apps Store
Issue I: Device Exclusivity
The issue with device exclusivity is that people have come up with ways to install this app on other devices. There are already modified versions of the app that overcome this - [PORT] Fortnite for Android with device check disabled (v5.2.0)
Then there are YouTube videos spreading on this topic:
We have already covered how YouTube videos are being used to propagate Fortnite related scams in one of our previous blog posts.
Issue II: Absence on Play Store
Another issue that may lead to serious implications is the fact that this app is not available on the official Android Playstore. This means users will have to allow "install from unknown sources" feature on their devices which is not safe. This may encourage users to take the dangerous route in the future as well.
Even before this, YouTube video scam has been propagating side-loading Fortnite apps. This move of not including Fortnite on PlayStore further encourages users to follow this route. However Google has taken a positive step by showing a notification that this app is not available on the Play Store to prevent users from installing a different app that may claim to be Fortnite:
We advise our readers to avoid installing Fortnite or any other app from a third party store as it falls outside Google's protective umbrella. It may be tempting to give this game a try but please avoid doing so until this app is fully supported on the Play Store.
Sonicwall Capture Labs continues to protect users from fake Fortnite apps via the following signatures: