Requirements for memory consumption by applications are being introduced in Android

Google has announced a new quality requirement for applications on the Android platform, aimed at reducing memory consumption by applications amid the shortage of RAM in the smartphone market. The requirements will come into effect in February 2027. Applications whose performance metrics exceed threshold values may face publication restrictions in the Google Play catalog and a decrease in visibility.

The metrics that will be monitored to identify issues with memory consumption:

  • Dynamic memory consumption (RSS + data swapped to the paging file) while the application is active and running in the background.
  • Memory usage for bitmap images, which should not occupy memory when the application is not displayed and operating in the background.
  • Optimization of executable code in DEX (Dalvik Executable) format. Applications should utilize tools such as R8 for DEX code optimization, removing unused constructs, and obfuscation (utilizing short names for classes, methods, and fields) to reduce the size of data loaded into memory.

Threshold values are defined based on the amount of RAM available on the device. For example, on devices with 4 GB of RAM, the application may use no more than 2 GB of memory while active and 1 GB while running in the background; on devices with 8 GB of RAM, 2.25 GB and 1.5 GB; with 12 GB of RAM—3.25 GB and 1.75 GB; and with 16 GB of RAM—4.25 GB and 2 GB, respectively. For games, the limits are higher: on devices with 4 GB of RAM, a game may use no more than 2.25 GB of memory while active and 2 GB while running in the background; on devices with 8 GB of RAM—3.5 GB and 2.75 GB; with 12 GB of RAM—4 GB and 3.2 GB; with 16 GB of RAM—5 GB and 3.5 GB.

In addition, requirements for seamless application transfer when changing devices are introduced. Starting April 2027, all applications, except for games, that support account sign-in must automatically restore their state when transferred to a new device using the Android Restore Credentials API.

Additionally, it should be noted that the Android 17 branch introduces features to enhance the security of network connections:

  • Enabling support for the TLS extension ECH (Encrypted ClientHello) for obfuscation domain in HTTPS traffic. ECH continues the development of the ESNI (Encrypted Server Name Indication) extension used for encrypting information about TLS session parameters, such as the requested domain name. The key difference between ECH and ESNI is that in ECH, instead of encrypting at the level of individual fields, the entire ClientHello TLS message is encrypted, allowing leaks through fields not covered by ESNI, such as the PSK (Pre-Shared Key) field, to be blocked.
  • Adding an authorization request for scanning the local network with applications or connecting to devices on the local network (Local Network Protection).
  • Enabling the CT (Certificate Transparency) mechanism by default, which provides a public log of all issued and revoked certificates. CT helps identify certificates created outside of the standard workflows of the certificate authority (for example, the covert creation of a certificate due to employee abuse or compromise of the certificate authority).
  • Mobile operators are provided with the option to disable support for 2G networks by default to block attacks that force smartphones to switch to 2G networks to bypass spam filtering mechanisms and deliver fraudulent SMS.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster