I have worked on an Android app extensively. I am pretty sure that's not possible.
I have worked on an Android app extensively. I am pretty sure that's not possible.
I was assuming they'd be doing something tricky like asking for INSTALL_PACKAGES (http://developer.android.com/reference/android/Manifest.perm...) and dropping something on the device. Thankfully they don't do that.
As someone who has hacked on Android before (ie: http://unrevoked.com), I wouldn't be surprised if there were ways to silently install packages, or even just tricking the user into allowing an install of a further package.
Quick googling leads to this: http://jon.oberheide.org/blog/2010/06/28/a-peek-inside-the-g...
No offense, but you're spreading some pretty false FUD. Unrevoked uses multiple exploits and requires a lot of user interaction and a computer to initiate the process.
Further that last link basically describes how Play remote installs applications and is all under the assumption that someone has somehow MITM the SSL connection, something I'm presuming is not at all easily done. (Further it's going on two years old, I wouldn't be shocked if Google is now signing their INSTALL_ASSET messages, Play has changed a LOT in the last two years).
Apps are sandboxed overall similarly in iOS, WinRT, Android, WP7. Uninstalling them, uninstalls them. It even removes all data attached assuming the dev doesn't manually put data on the SD card instead of using the API to store data on the SD card.
http://blog.duosecurity.com/2011/05/when-angry-birds-attack-...
Another variation of that attack is still unpatched, allowing any app to invoke INSTALL_ASSET. Certainly that's not intended functionality and is a bug that will be (eventually) patched, but I wouldn't classify it as FUD.