Possible security issue? Update Failed: "Package com.x8bit.bitwarden signatures do not match previously installed version; ignoring!" #1472

Closed
opened 2025-11-26 22:50:04 -06:00 by GiteaMirror · 1 comment
Owner

Originally created by @WillyWonksters on GitHub (Jul 22, 2022).

Steps To Reproduce

  1. Install Bitwarden through official f-droid repo.
  2. Attempt to update through Aurora Store (I expect the play store to have the same result).

Expected Result

App is updated.

Actual Result

INSTALL_FAILED_UPDATE_INCOMPATIBLE: Package com.x8bit.bitwarden signatures do not match previously installed version; ignoring!

Screenshots or Videos

The failed update in the Aurora Store.
IMG_20220721_225506

This is the result of Checkey, when analyzing v2022.6.1
IMG_20220721_223750

Additional Context

The checksums of my installed APK (according to Checkey) do not match any of the 2022.6.1 files hosted on github. Should I be concerned that I somehow installed a malicious APK?

sha256sum com.x8bit.bitwarden.apk
cfc766340388d38b7fde27835770de661c350419b05b71b84f3dcd9ce7e3ab8d com.x8bit.bitwarden.apk

sha256sum com.x8bit.bitwarden-fdroid.apk
b39d1710465b8589be6b0d3f0cec2ee8ab9db645cf7c57ef3e399baae7e023a7 com.x8bit.bitwarden-fdroid.apk

sha256sum com.x8bit.bitwarden.aab
b8115b1f9830d0a62924db8472b2288c0428662203fe27b11c99dcea9949dc47 com.x8bit.bitwarden.aab

Operating System

Android

Operating System Version

GrapheneOS

Device

Pixel 5

Build Version

Version: 2022.6.1 (4795)

Beta

  • Using a pre-release version of the application.
Originally created by @WillyWonksters on GitHub (Jul 22, 2022). ### Steps To Reproduce 1. Install Bitwarden through official f-droid repo. 2. Attempt to update through Aurora Store (I expect the play store to have the same result). ### Expected Result App is updated. ### Actual Result INSTALL_FAILED_UPDATE_INCOMPATIBLE: Package com.x8bit.bitwarden signatures do not match previously installed version; ignoring! ### Screenshots or Videos The failed update in the Aurora Store. ![IMG_20220721_225506](https://user-images.githubusercontent.com/68391808/180352973-f636aba0-ad01-482d-ac7e-42528c8a093e.jpg) This is the result of Checkey, when analyzing v2022.6.1 ![IMG_20220721_223750](https://user-images.githubusercontent.com/68391808/180352943-15b62d81-0a30-48c8-bd47-9c7486f8cd1f.jpg) ### Additional Context The checksums of my installed APK (according to Checkey) do not match any of the 2022.6.1 files hosted on github. Should I be concerned that I somehow installed a malicious APK? sha256sum com.x8bit.bitwarden.apk cfc766340388d38b7fde27835770de661c350419b05b71b84f3dcd9ce7e3ab8d com.x8bit.bitwarden.apk sha256sum com.x8bit.bitwarden-fdroid.apk b39d1710465b8589be6b0d3f0cec2ee8ab9db645cf7c57ef3e399baae7e023a7 com.x8bit.bitwarden-fdroid.apk sha256sum com.x8bit.bitwarden.aab b8115b1f9830d0a62924db8472b2288c0428662203fe27b11c99dcea9949dc47 com.x8bit.bitwarden.aab ### Operating System Android ### Operating System Version GrapheneOS ### Device Pixel 5 ### Build Version Version: 2022.6.1 (4795) ### Beta - [ ] Using a pre-release version of the application.
GiteaMirror added the bug label 2025-11-26 22:50:04 -06:00
Author
Owner

@aj-bw commented on GitHub (Aug 22, 2022):

Hi @WillyWonksters! Thanks for reaching out.

It would be expected to receive errors attempting to apply Aurora Store updates to an instance installed from F-Droid. The app in F-Droid would have a different signature from the app in the Play Store ( or Aurora Store in this case ), this is mentioned here in our FAQs: https://bitwarden.com/help/product-faqs/#q-can-i-install-bitwarden-without-google-play,-for-instance-on-f-droid

Please attempt to process the updates in F-Droid or Aurora Droid ( alternative front end for F-Droid ), or delete the F-Droid version, reboot and install from Aurora Store if you wish to receive your updates there.

I will close this GitHub issue, but if any issues were to persist please feel free to contact us using our Contact page. You can include a link to this issue in the message content.

@aj-bw commented on GitHub (Aug 22, 2022): Hi @WillyWonksters! Thanks for reaching out. It would be expected to receive errors attempting to apply Aurora Store updates to an instance installed from F-Droid. The app in F-Droid would have a different signature from the app in the Play Store ( or Aurora Store in this case ), this is mentioned here in our FAQs: https://bitwarden.com/help/product-faqs/#q-can-i-install-bitwarden-without-google-play,-for-instance-on-f-droid Please attempt to process the updates in F-Droid or Aurora Droid ( alternative front end for F-Droid ), or delete the F-Droid version, reboot and install from Aurora Store if you wish to receive your updates there. I will close this GitHub issue, but if any issues were to persist please feel free to contact us using our [Contact page](https://bitwarden.com/contact)[.](https://bitwarden.com/contact.) You can include a link to this issue in the message content.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#1472