That's correct. Android will warn you if the signatures don't match too. Even if we're in the full-on conspiracy theory territory of Google disabling that core security feature, impersonating a third-party developer, and dropping a binary onto a single user's phone, they still couldn't fake the signature.