Windows 11 app store may create security issues

Windows 11
(Image credit: Microsoft)

Alarm bells are beginning to be raised over perceived limitations of the new-look Microsoft Store, which was unveiled last month at the Windows 11 launch.

During the event, Microsoft celebrated the fact its new store will be open to a much wider range of third-party applications built on a larger selection of frameworks, including Win32, .Net, UWP, Java and more.

However, the store’s terms and conditions reveal that the update process will differ slightly depending on application type. Namely, users of software “packaged as a Win32 app” will not receive updates from the Microsoft Store directly, but will be responsible for installing patches manually via the application itself.

Beyond the inconsistent user experience, commentators have suggested this quirk will allow updates to circumvent Microsoft’s checks and balances, which are designed to ensure only legitimate applications are distributed via the store. Previously, Microsoft had claimed all applications hosted on the store will be “tested for security, family safety and device compatibility”.

Microsoft Store on Windows 11

When Microsoft announced it would deliver a much-needed upgrade to its official app marketplace, the greatest emphasis was placed on the visual overhaul, which will bring the store in line with the Windows 11 aesthetic.

The introduction of Android applications to Microsoft Store also drew headlines. With Windows 11, users will be able to run Android apps directly from their desktop, albeit only those hosted on Amazon’s app store.

However, it appears closer attention is now being paid to the inner workings of the marketplace and how this might affect the end user.

On Twitter, Microsoft developer Scott Hanselman called criticism of the app store’s update process “misleading”. “Apps can use MSIX and update. It says on each app page if it updates itself or if the store does. It’s pretty clear,” he noted.

Here, he refers to the fact that Win32 apps can be packaged as MSIX (a Windows app package format) in order to receive automatic updates via the Microsoft Store. MSIX can be considered an evolution of MSI, an older package format that will not be compatible with auto updates.

However, as another Twitter user points out, MSIX is currently only used by a minority of applications. The Register, meanwhile, suggested it is impractical to ask users to understand the difference between MSIX and MSI.

Microsoft has not yet responded to our request for an official response to the security concerns and clarification over whether the company will seek to create consistency in the update process across all app types.

Update:
A Microsoft spokesperson has since provided the following statement: 

"Microsoft Store is committed to protecting our customers’ security and privacy. It is a priority for Microsoft to ensure that all our products and services comply with applicable law. We vet developers who publish to the Microsoft Store on Windows 11, and the apps that are installed have undergone security and device compatibility checks.”

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Windows 11 forced onto old hardware
Windows 11 is still my favorite OS, ads and all
Angry businessman destroying his desk and laptop with a baseball bat
New patch for Windows 11 24H2 reportedly plays havoc with File Explorer, and some folks are claiming it's broken their PC
A laptop with the Windows 11 desktop on screen, glowing, while on a work desk
Are you unable to get security updates for Windows 11 24H2? Here’s the likely reason why, and the fix to get your PC safe and secure again
Windows 10 Fail
I have good news and bad news about Windows 11 24H2’s new update: it introduces nifty features and fixes... but also includes another ad
Angry businessman destroying his desk and laptop with a baseball bat
I'm absolutely sick of Microsoft's Windows 11 24H2 update, as it's now causing Bluetooth and webcam issues
A man sitting at his computer desk on his desktop with his head in his hands, looking a little frustrated.
Windows 11 suffers more bugs in latest update, with the Start menu hit hard by some frustrating issues
Latest in Pro
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Customer service 3D manager concept. AI assistance headphone call center
The era of Agentic AI
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
A hand reaching out to touch a futuristic rendering of an AI processor.
Balancing innovation and security in an era of intensifying global competition
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off