But they're not doing that. So clearly their goal is something else.
You don't even need to do that – for a while already, Google's toolchain has been adding dependency metadata to all apps by default (encrypted, though, so only Google can read it) and they've indeed been using that to warn about outdated or vulnerable dependencies. According to https://support.google.com/googleplay/android-developer/answ..., at most they'll only block you from releasing further updates including dependencies with critical vulnerabilities, though…
I'm more an infra guy, and such scans are actually absolutely awesome. I see everything in my k8s clusters, all java/python dependencies that need attention.
I'm more surprised how anyone can run an app for more than 2 weeks with no high severity vulnerabilities. I guess mobile doesn't have the same attack vectors, but still
Sure, you can bend your scope to make them relevant... but if you've got someone who can control your system in ways you didn't build by bypassing the OS protections, they already have control of the device and can do darn near anything. If you haven't protected from that, and it's frequently not possible, many other protections are meaningless.
Your backend though has to handle this kind of malicious-modified-client scenario, as well as random connections from code you don't control at all.
(This is not true for all apps of course, but for B2B stuff? Most small companies? Frequently valid)
And we can ignore the shovelware, which probably is actually a majority of apps. Those won't care about security patches, and will probably go out of their way to hide them so they don't appear vulnerable and don't have to do maintenance releases. They wouldn't be affected by forced updates.
I am sticking to android ecosystem as best one I know, because I still have choices + I can use fdroid for a lot of my apps.
But when my mom uses a tablet or phone ... I have absolutely no smart advise to give her. All apps are hostile and annoying. The play game subscription is fine (apps/games cannot have apps and are fully unlocked) but other that that play store is a minefield.
User installs the game, has fun, uninstalls or leaves it there where only they can run it.
But if that random game should, say, fetch user avatars from the web, then untrusted input to a way out of date image decoding library would be a nice path to a remote code execution vulnerability.
Or if the app registers any intent handlers that other apps and websites can trigger, or establishes TLS connections to any third party site, or...
The message is that the app developer in question's argument that they have nothing to update is most likely false, not that special industries is a driver for the policy.