Skip to content

HDFC Bank App: Banking & Cards #799

@jayb-g

Description

@jayb-g

Is there an existing issue for this?

  • I have searched the existing issues

App name

HDFC Bank App (Early Access)

Link to app

https://play.google.com/store/apps/details?id=com.hdfcbank.android.now

App version

7.1.6

Country of the app

India

Build Number

2025110801

Device list

Pixel 8a, Pixel 9, Pixel 8

Profile app tested in

Owner profile, Work profile (Add details in extra notes below, i.e., device manager app name)

Google Play installed?

Tested with:

  • Installed
  • Not Installed

with same results

Where did you install this app from?

Aurora Store

Native code debugging

  • Allowed
  • Blocked

Exploit protection compatibility mode

  • Enabled
  • Disabled

Memory tagging

  • Enabled
  • Disabled
  • N/A

Dynamic code loading via memory

  • Restricted
  • Allowed

Dynamic code loading via storage

  • Restricted
  • Allowed

Does the app use the Play Integrity API?

  • Yeah
  • Yea, blocked
  • Nope (No such notification)

NFC payments

  • Works
  • Works but requires another service
  • Does not work
  • N/A (Not supported by app)
  • Not tested

Description of the app's functionality

As many HDFC users may have already experienced this, HDFC is replacing its existing HDFC Bank MobileBanking App with a new HDFC Bank App, despite the old existing app working fine in all aspects in GOS even without Play Services installed; probably an overhaul of their app with more features. Anyway, this new app apparently is not usable at all when installed in GOS. I have also tried the possible workarounds but none of them seem to work.

  1. For some users(early access) the old HDFC app forcefully shows prompt to redirect users to the new app(which happened in my case), despite the same version of old app working fine for another HDFC account in GOS. Eventually this will be rolled out for all HDFC users and GOS users won't be able to use it at all.
  2. When the new app is installed and opened, within few seconds it shows Alert! Unsecured Device and shows a know more link and an option to close the app. Although I have not done any of the things mentioned, no remote access apps , no USB debugging enabled. It doesn't even matter if Google Play services are installed or not. It behaves the same.

Possible causes:

The New App uses either:

  • Google Play Integrity or SafetyNet Attestation API
  • Checks if app is installed from Google Play store
  • or both

Possible Solutions:

  • Try installing from Google Play store (I have not tested that as I don't have a burner Google account)
  • Contact HDFC Bank using the template adding any other obervations of your own. Or HDFC fixes whatever is causing this on its own in coming versions.
  • HDFC Bank updates the old app removing the mandatory switch to the new App and making it optional so that users can choose to continue to use the old App. But even if they do, this will be temporary, say up to 6 months or a year and eventually everyone will have to move to the new App.

Are there any extra notes you think users should know about?

Also tested with Play Services installed in work profile with Shelter.

ADB logcat of the app if necessary

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions