Google Play backdoors policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps with remote commands, dynamic execution, or unintended privileged entry points.

A backdoor finding concerns code that enables unwanted, potentially harmful operations under remote control. The entry point matters even when the harmful action hasn’t run during your own testing.

What to check

Inspect command handlers, remote configuration, dynamically loaded code, exported components, and SDK control channels. Identify who can invoke each operation and what data or device functions it can reach.

Google distinguishes a backdoor from some vulnerabilities based on the enabled behavior and evidence of harmful purpose. Either finding needs investigation; renaming the mechanism won’t remove the risk.

How to address the rejection

Remove the harmful command path or vulnerable execution mechanism. Restrict legitimate interfaces to the operations and callers they actually need, and remove obsolete debug endpoints from release builds.

Test the previously flagged entry point against the corrected artifact. In your response, describe the reachable operation, the dependency or component involved, and the change that prevents it. Don’t rely only on saying the remote feature is currently disabled.

Messages this guide can help with

Backdoors; Backdoors policy violation; Backdoors rejection; Backdoors denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access