EMZETT.
Login

APK

In short: “Android Package” — the file format in which Android apps are packaged and installed, comparable to a .exe on Windows.

In more detail: An APK is technically a ZIP archive with the compiled app code, resources (images, layouts) and a manifest describing permissions and app info. Normally apps are installed via the Play Store, but APKs can also be installed directly (“sideloading”) — practical for testing, but without the Play Store’s security review.

In Depth

Internal structure

Because an APK is ultimately just a renamed ZIP archive, its content can be opened and inspected directly with common archive tools (e.g. 7-Zip) — it contains, among other things, AndroidManifest.xml (permissions like camera/location access, app name, minimum Android version), classes.dex (the compiled bytecode optimised for the Android runtime — DEX stands for “Dalvik Executable”, after the original Android runtime, Dalvik), and resource folders for images at various screen resolutions (so the same app icon looks sharp on both a small smartphone and a large tablet).

Signing as a security mechanism

Every APK has to be digitally signed before it’s installable — the signature proves an update really comes from the same developer as the original version (otherwise Android refuses to overwrite an existing app, even if the name and icon look identical). This signature check protects against someone smuggling in a malicious, tampered version of a known app as an “update”.

App bundles as the modern standard

For distribution via the Play Store itself, Google now mostly uses the newer app-bundle format (.aab, “Android App Bundle”), from which the store generates a suitably tailored, smaller APK for each specific device — containing, for example, only the image resources and processor-architecture binaries actually needed for that device, instead of bundling all possible variants into a single large file. The classic APK format nevertheless remains the standard for direct distribution outside the Play Store (sideloading, alternative app stores like F-Droid).

Security risks of sideloading

Normally apps are installed via the Play Store, but APKs can also be installed directly (“sideloading”) — practical for testing your own apps before release, for apps outside the Play Store (e.g. F-Droid for exclusively open-source apps), or in regions without full Play Store access. Without the Play Store’s security review (which, among other things, scans APKs for known malware signatures), the user bears the full risk themselves with sideloading — one of the most common distribution routes for Android malware is fake APKs of popular apps outside official stores.

Permission model

The AndroidManifest.xml lists all the permissions an app potentially wants to use (camera, location, contacts, internet access, etc.). Up to Android 5, these permissions were granted as a blanket approval at install time — the user had to agree to all or none. Since Android 6, the system instead asks for most sensitive permissions at runtime, at the specific moment the app actually needs them (e.g. the first time the camera feature is opened) — a considerably more granular, user-friendly model that also allows individual permissions to be revoked later without uninstalling the app.

See also: Android, ZIP