A live update replaces files the WebView loads. Anything compiled into the APK or read by Android before the WebView starts stays as it was until the next store release:
| Change | Live update? | Why |
|---|---|---|
| HTML, CSS, JavaScript, images, fonts | Yes | Served from the bundle directory |
| A new plugin or a plugin upgrade | No | Native code in the binary |
| Permissions, intent filters, Info.plist | No | Read by the OS at install time |
| capacitor.config.ts, icons, app name | No | Native assets and resources |
So a bundle must be compatible with the native code it lands on: a call to a plugin the installed binary lacks fails with UNIMPLEMENTED (Bridge Errors).
The stores allow this within limits. Google Play 1 's Device and Network Abuse policy forbids downloading executable code "such as dex, JAR, .so files" from outside Play, but exempts "code that runs in a virtual machine or an interpreter", naming JavaScript in a WebView. Apple's Developer Program License Agreement allows downloaded interpreted code that does not change the app's primary purpose, create a storefront, or bypass security features.