VMTech
Discuss a project →

Android 17 limits accessibility services under Advanced Protection

Android 17 limits accessibility services under Advanced Protection

Google has announced that Android 17 will restrict access to the Android AccessibilityService API when Advanced Protection is enabled. Under the new control, only verified applications classified as Accessibility Tools will be allowed to use accessibility services. Google says the measure is designed to close a major attack path used by malicious Android applications in malware and financial-fraud campaigns.

Advanced Protection is an Android security setting that enables the platform's available protections against potential threats. In Android 17, the accessibility restriction is applied automatically when the setting is turned on, while retaining access for verified assistive applications.

Privileged API has been repeatedly abused

Android's AccessibilityService framework is intended to support users with disabilities through functions such as screen readers and voice-control systems. It is also a powerful API: an application can operate in the background, intercept user-interface events and interact with other applications on a user's behalf.

That level of access has made the service a target for banking trojans and spyware. Once a victim is persuaded to enable an accessibility service through social engineering, malicious software can use genuine assistive capabilities to initiate fraudulent transfers from financial apps, log keystrokes, display counterfeit login screens over legitimate apps and grant itself additional sensitive permissions without root access.

Google also noted that hostile applications can exploit screen-level access to read sensitive data, install malware or interfere with removal. The Android 17 change narrows this route by allowing Advanced Protection users to grant AccessibilityService access only to verified apps in the Accessibility Tools category.

Additional protections in Android 17

The change builds on prior Android safeguards. Google has blocked sideloaded apps from enabling accessibility services and added in-call protections intended to stop users from disabling Google Play Protect, sideloading applications or granting accessibility permissions while on a call. Developers can also use the accessibilityDataSensitive flag to identify views or composables containing sensitive data and prevent potentially malicious applications from accessing or interacting with that content.

Android 17 also introduces Intrusion Logging, described as persistent and privacy-preserving forensic logging for investigations of sophisticated spyware attacks. It adds USB Protection against unauthorized access through a physical USB connection, an option to disable WebGPU to reduce exposure to sophisticated browser-based exploits, and Failed Authentication Lock to lock down a device after failed authentication attempts.

Other additions include View Supporting Apps, which lets users see installed applications that have checked Advanced Protection status. Google says developers can be notified when Advanced Protection is enabled and can automatically activate features intended for that user group. Users who already have the setting enabled will receive a notification when the new capabilities reach their devices; Intrusion Logging must be manually enabled from the Advanced Protection settings page.

Business implication

Organizations managing Android devices should determine which business-critical accessibility applications are verified and classified as Accessibility Tools before adopting Android 17 protections. They should also review whether Advanced Protection, Intrusion Logging and the new device controls fit their mobile security and incident-investigation procedures.

#androidsecurity#mobilesecurity#malware#accessibility
Open analytics
On the site 3 views
min read 4 02.10.2026
Instagram

Android 17 limits accessibility services under Advanced Protection

Open the post on Instagram ↗