Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Former national security officials and scholars warned that the Epic-Google injunction could create serious cybersecurity risks. That warning is their argument in a brief supporting Google—not a finding that the ruling caused an attack or that catastrophic harm is inevitable. The Ninth Circuit upheld the antitrust verdict and injunction, while saying Google may take reasonable security measures.

What did the court rule in the Epic-Google fight?

Epic Games sued Google over how Android apps are distributed and paid for through Google Play. A jury found Google liable under antitrust law, and the district court entered a permanent injunction on October 7, 2024.

On July 31, 2025, the Ninth Circuit upheld both the jury’s antitrust liability finding and the injunction. Its opinion addressed Google’s security concerns, noting that the order allows reasonable measures to protect platforms, app stores, and apps. The ruling did not find that the injunction had caused a cybersecurity incident.

What does the injunction require about app stores?

The dispute concerns provisions that require greater access to Google Play’s app catalog and permit third-party app-store distribution and developer links. The order also establishes a Technical Committee to help resolve technical disputes. Those provisions are central to the security disagreement: the amici say they could restrict Google’s ability to control distribution and react to threats; the court points to security protections written into the injunction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The available account does not set out every technical condition or implementation detail in those provisions. It is therefore more accurate to describe their broad effect than to assume the order requires Google to approve every app, abandon screening, or provide unrestricted access in every circumstance.

Why do former officials warn of cybersecurity risks?

In an August 25, 2025 amicus brief supporting Google’s rehearing request, former officials and scholars argued that third-party stores and links to apps could expose users to malicious software. They said broader catalog access and limits on Google’s control over distribution could make it harder to screen stores, contain harmful apps, and respond as threats change. They also questioned whether the Technical Committee and district court could manage security disputes at the scale involved.

The brief used the phrase “massive cybersecurity vulnerabilities in the online ecosystem.” Its authors offered qualitative predictions and examples, not a measured estimate of the additional risk created by this particular injunction. No independently verified, directly comparable statistic quantifying that incremental risk is established in the cited materials.

Who signed the warning?

The brief identifies its amici collectively as former national security officials and scholars. CyberScoop’s August 26, 2025 report names signatories including Tatyana Bolton, a former cyber policy lead at CISA; Joel Brenner, a former NSA inspector general and former ODNI counterintelligence head; Paul Lekas, a former Defense Department deputy general counsel; John Shanahan, a former director at the Defense Department’s Joint Artificial Intelligence Center; Joseph Anderson, a former Army official; Steven Bellovin, a former FTC chief technologist; David Shedd, a former deputy director of the Defense Intelligence Agency and former National Security Council official; and Gene Tsudik, a computer science professor at the University of California, Irvine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What security safeguards did the Ninth Circuit identify?

The court’s response was that the injunction expressly preserves reasonable security protections. In its September 12, 2025 order, the Ninth Circuit said the injunction addresses security risks through reasonable measures “to ensure that the platforms or stores, and the apps they offer, are safe from a computer systems and security standpoint.” It also described the Technical Committee as a way to help resolve technical disputes, including security concerns.

That is the court’s explanation of the order’s safeguards, not proof that every possible security problem has been eliminated. The amici dispute whether those safeguards and the dispute-resolution process are adequate for threats that may change quickly. The sources cited here do not establish a published risk assessment that settles that disagreement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is the injunction still being appealed?

On September 12, 2025, the Ninth Circuit denied Google’s requests for a stay and rehearing. It said Google had not met the required showing of likely reversal or irreparable harm, and it rejected national security as a basis for a stay in that motion. The order extended the compliance timeline for injunction paragraphs 11 and 12 to ten months after issuance of the mandate; that extension was specific to those paragraphs.

Google later petitioned the U.S. Supreme Court for review. The Supreme Court docket for Google LLC, et al. v. Epic Games, Inc., No. 25-521, records that the petition was dismissed on March 9, 2026, after the parties jointly stipulated to dismissal. The docket, checked September 28, 2026, showed no reinstatement. That dismissal was not a Supreme Court ruling on the merits. The cited docket is the latest verified appellate development described here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.