spoofing-your-location-in-play-store.md (5605B)
1 --- 2 title: "Spoofing Your Location in Google Play Store" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/spoofing-your-location-in-play-store.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/spoofing-your-location-in-play-store.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Spoofing Your Location in Google Play Store 14 15 Google Play storefront georestrictions are usually enforced by a mix of **Play country / billing profile**, **network geolocation**, and **cached Play state** — not only by the phone GPS. Therefore a VPN alone sometimes works, but in newer Play flows you usually also need to reset cached state and, for real country/profile switches, use an account/payment profile that matches the target country. 16 17 If your goal is only to **obtain the APK for reversing**, it is often easier to use the alternative acquisition workflow documented in [Android Applications Pentesting](/hacktricks/mobile-pentesting/android-app-pentesting/overview) instead of fighting the storefront. 18 19 ## What Google Play Actually Checks 20 21 - **Current network location** (the country seen from the exit IP). 22 - The **Google Play country/profile** attached to the account and Google Payments profile. 23 - Cached state in **`com.android.vending`**, **`com.google.android.gms`**, and **Download Manager**. 24 - Whether the package is **published in that country** by the developer. 25 - In some cases, **device certification / integrity** (this is a different problem from pure region spoofing). 26 27 If an app is hidden because the device is not **Play-certified** or fails attestation, check [Play Integrity attestation spoofing](/hacktricks/mobile-pentesting/android-app-pentesting/play-integrity-attestation-bypass). 28 29 ## Fast Path on a Non-Rooted Device 30 31 1. **Connect to a VPN** endpoint in the target country. 32 2. Prefer a **fresh test Google account** already configured for that country. Reusing an account from another country often triggers the _selected Play country matches your country of residence_ error. 33 3. **Clear Play state** from the GUI or directly with `adb`: 34 35 ```bash 36 adb shell am force-stop com.android.vending 37 adb shell pm clear com.android.vending 38 adb shell am force-stop com.google.android.gms 39 adb shell pm clear com.google.android.gms 40 adb shell am force-stop com.android.providers.downloads 41 adb shell pm clear com.android.providers.downloads 42 ``` 43 44 4. Re-open **Play Store** and inspect **Settings --> General --> Account and device preferences --> Country and profiles**.<sup>[[1]](#references)</sup> 45 5. If the target country/profile appears, switch to it and retry the install. Google Play profile changes can take **up to 48 hours** to fully update. 46 6. If the country/profile does not appear, remember that Google expects you to be **in the target country** and to have a **payment method from that country** when creating a new Play country/profile. 47 48 ## Rooted / Emulator Workflow 49 50 When the target app checks GPS after installation, align the device geolocation with the storefront country: 51 52 - **Android Emulator**: send a GPS fix directly to the emulator:<sup>[[3]](#references)</sup> 53 54 ```bash 55 adb -e emu geo fix -3.7038 40.4168 # longitude latitude (Madrid) 56 ``` 57 58 - **Physical device**: enable **Developer options --> Select mock location app** and set your GPS spoofer as the mock provider. If you need to do it from the shell: 59 60 ```bash 61 adb shell appops set <MOCK_LOCATION_APP_PKG> android:mock_location allow 62 ``` 63 64 ## Bypassing App-Side Mock-Location Checks 65 66 Modern Android apps can detect lab GPS spoofing by calling **`Location.isMock()`** (API 31+) or the legacy **`isFromMockProvider()`**. On an authorized rooted lab, LSPosed modules such as **HideMockLocation** or a Frida hook can neutralize these checks:<sup>[[2]](#references)</sup><sup>[[4]](#references)</sup> 67 68 ```javascript 69 Java.perform(function () { 70 const L = Java.use('android.location.Location'); 71 try { L.isMock.implementation = function () { return false; }; } catch (e) {} 72 try { L.isFromMockProvider.implementation = function () { return false; }; } catch (e) {} 73 }); 74 ``` 75 76 Keep the hook scoped to the **target app** when possible: the Play Store itself is mostly country/profile/IP driven, while the **installed app** is the component that commonly performs the GPS/mock-location check. 77 78 ## Common Failure Modes 79 80 - A **VPN only changes the IP**; it does not rewrite the Google Payments profile behind the account. 81 - Clearing only **Play Store** is frequently insufficient; also reset **Google Play services** and **Download Manager**. 82 - Google currently enforces a **cooldown between Play country changes**, and **Family group** membership can block switching countries. 83 - Even after installation, the app backend may still geofence you using **GPS, IP, SIM MCC/MNC, phone number, locale, or server-side KYC**. 84 - Some install failures are actually **Play Integrity / certification** failures rather than country failures. 85 86 ## References 87 88 - [1] [Google Play Help: How to change your Google Play country](https://support.google.com/googleplay/answer/7431675?hl=en) 89 - [2] [HideMockLocation (LSPosed/Xposed)](https://modules.lsposed.org/module/io.github.auag0.hidemocklocation/) 90 - [3] [Android Emulator console - `geo fix`](https://developer.android.com/studio/run/emulator-console#geo) 91 - [4] [Android `Location.isMock()` API](https://developer.android.com/reference/android/location/Location#isMock())