When you search for an app, google will happily allow attackers to buy that result and direct mislabeled links to the attackers' site. A former ceo got his laptop owned that way trying to install Adobe Acrobat because he unfortunately trusted google and thought the first result for a search for Adobe Acrobat would be legit. I was quite annoyed about having to clean up his laptop but you have to be relatively sophisticated not to get taken in.
This continues to be a problem; from the article, see eg this ad for Bitwarden:
https://x.com/KarlEmilNikka/status/1792554054893072672
Google allows the attacker to target navigational queries (in this case, bitwarden) and display "www.bitwarden.com" as the link text on a link that does not actually go to www.bitwarden.com .
The root cause is Google are parasites that (1) monetize navigation / install queries; and (2) force you to buy ads on your own company's name [1]. This opens the gate to attacks like the above, which they also don't effectively police.
[1] https://nymag.com/intelligencer/2019/03/why-businesses-have-...