- Google restricts Android’s accessibility services to verified apps when Advanced Protection is enabled, closing a major attack pathway.
- Malicious apps have abused the AccessibilityService API to steal data, log keystrokes, and initiate fraudulent transactions.
- Android 17 introduces Intrusion Logging, USB Protection, Failed Authentication Lock, and other security improvements.
- Developers can receive notifications when Advanced Protection is active to auto-enable features for that user population.
Google announced a new security measure that limits access to Android’s accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled, according to the company on Thursday. The move blocks malicious apps that have exploited the AccessibilityService API to conduct financial fraud and malware attacks without root access.
“In Android 17, enabling Advanced Protection automatically restricts AccessibilityService access exclusively to verified applications categorized as Accessibility Tools, closing off a major avenue of attack while preserving vital assistive technology,” Google stated. Banking trojans and spyware have abused the powerful API to extract sensitive data, draw fake login screens, and grant themselves additional permissions. Google warned, “because accessibility services are designed to interact directly with the screen, malicious actors can exploit them to read sensitive data, install malware, or block uninstallation.”
Consequently, Android 17 also brings Intrusion Logging for persistent, privacy-preserving forensics, USB Protection against physical attacks, and a Failed Authentication Lock to prevent brute-force tampering. Developers can be notified when Advanced Protection is enabled to auto-enable features for this user population. Users must navigate to Advanced Protection settings to manually enable Intrusion Logging.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
