- Google says Android 17's Advanced Protection limits accessibility services to verified Accessibility Tools. Google calls these services a primary vector for fraud and scams.
- The rule removes a permission scammers persuade people to grant, but only for users who turn Advanced Protection on. Google does not say how apps get verified.
- Leaders should decide which staff need the setting and check whether any business app relies on accessibility services.
Android 17 removes one permission scammers rely on, for users who opt in
This kind of attack does not need to break the phone. The Hacker News says it starts when the owner is tricked into switching the service on. Android 17 targets that step.
With Advanced Protection on, only verified apps in an Accessibility Tools category can use Android's AccessibilityService API. Other apps are shut out. Google describes the API as a primary route for fraud and scams, and says assistive apps keep working.
This suggests a useful way to read the change. The user no longer has to judge whether an app deserves this permission. For those users, the permission is simply unavailable.
That holds only for people who turn the setting on. Everyone else still faces the decision. Google's post does not say whether a user can switch Advanced Protection off again later.
How the abuse works
The API was built for screen readers and voice control. The Hacker News describes it as a framework that lets an app run in the background, watch what happens on screen and act inside other apps for the user.
That reach is what attackers want. Google says abusers can use it to view sensitive data, plant malware or stop an app from being removed. The Hacker News reports that banking trojans and spyware have used it without root access.
In the scenario The Hacker News describes, the path begins with a trick. The victim is persuaded to switch the service on. After that, the malware can move money out of banking apps and record typing. It can also paint fake login screens over real ones and give itself more permissions.
What "verified" leaves unanswered
Google's post does not explain how apps are verified or placed in the Accessibility Tools category. The criteria are not stated.
That matters for legitimate software. A business app that uses the API for another purpose might not qualify. The sources do not say either way.
The Hacker News lists an earlier Advanced Protection step that stopped certain kinds of apps from using the API. The new rule instead names who may use it. The sources do not detail how the two differ beyond that.
A layered fix, not a single switch
This is one of several steps against the same abuse. The Hacker News lists earlier ones. Sideloaded apps can no longer enable accessibility services. In-call protections stop users from disabling Google Play Protect or granting accessibility permissions. A flag lets developers mark screens that hold sensitive data.
Android 17 also adds Intrusion Logging. Google says security and network events are encrypted end to end and stored in the cloud. They are deleted after a rolling 12 months. Users must opt in to it separately.
USB Protection defaults a locked device to charging only for new connections. WebGPU, a browser graphics feature, is turned off to reduce exposure to browser-based exploits. Failed Authentication Lock fully locks the device after repeated failed attempts.
What the announcement does not tell you
Google gave no figures on how much fraud this removes. The claim that the API is a primary vector is Google's own.
Coverage has limits too. Advanced Protection is a setting people choose. Two features, USB Protection and Failed Authentication Lock, reach only select Android 17 devices. Google notes that, depending on hardware, the USB feature may affect a locked device, such as charging speeds.
So this protects the people who turn it on. It does not protect a workforce by default.
What leaders should ask
Start with who is most exposed: executives, finance approvers and staff with a public profile. Ask whether they use Android 17 devices and whether Advanced Protection is on for them.
Ask the mobile management team if the setting can be encouraged or checked through device policy. Google's post does not say whether it can be enforced. Confirm with your vendor.
Ask which business apps depend on accessibility services. An app outside the verified category may stop working for users with the setting on. Google says apps can learn when Advanced Protection is on, so developers can enable extra safeguards for those users.
Finally, decide who should turn on Intrusion Logging. It is optional. Logs only help an investigation if they were switched on before the incident.
The feature does not fix social engineering. For those who opt in, it closes off an avenue Google calls a primary vector.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Google.





