Back to Feed
VulnerabilitiesOct 2, 2026

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Android 17 Advanced Protection restricts accessibility services to verified apps.

Summary

Google is enhancing Android's security in version 17 by restricting access to accessibility services to only verified applications when Advanced Protection is enabled. This move aims to block a significant attack vector used by malicious apps for malware distribution and financial fraud, leveraging the powerful AccessibilityService API.

Full text

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools Ravie LakshmananOct 02, 2026Mobile Security / Android Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a security setting that turns on all Android's security features to secure the device against potential threats. "In Android 17, enabling Advanced Protection automatically restricts AccessibilityService access exclusively to verified applications categorized as Accessibility Tools, closing off a major avenue of attack while preserving vital assistive technology," Google said Thursday. The Android AccessibilityService API is a powerful framework that allows an application to run in the background, intercept user interface events, and interact with other applications on the user's behalf. Although its primary purpose is to assist users with disabilities, such as through screen readers or voice control systems, its privileged access has been abused by banking trojans and spyware to extract sensitive data and perform malicious actions without needing root access. Put differently, once a user is tricked into enabling the service under a social engineering pretext, the malware can turn genuine assistive features into potent cyber weapons to programmatically initiate fraudulent fund transfers from installed financial apps, log keystrokes, draw fake login screens over legitimate apps, and grant itself additional sensitive permissions. "Because accessibility services are designed to interact directly with the screen, malicious actors can exploit them to read sensitive data, install malware, or block uninstallation," Google said. In recent years, Google has taken a number of steps to counter this abuse - Blocking sideloaded apps from enabling accessibility services In-call protections that prevent users from disabling Google Play Protect, sideloading apps, or granting accessibility permissions Setting the accessibilityDataSensitive flag to let app developers mark a view or composable as containing sensitive data to block potentially malicious apps from accessing sensitive view data or performing interactions on it Using Android Advanced Protection Mode (AAPM) to prevent certain kinds of apps from using the accessibility services API Alongside Accessibility protection, Android 17 also brings a number of other security improvements - Intrusion Logging, which enables persistent, privacy-preserving forensics logging to investigate sophisticated spyware attacks USB Protection, which prevents attackers from gaining unauthorized access to your device through a physical USB connection Disable WebGPU, which reduces exposure to sophisticated browser-based exploits Failed Authentication Lock, which protects against physical tampering and brute-force attempts by completely locking down the device to prevent further probing View Supporting Apps, which allows users to view which installed apps have checked the Advanced Protection status "Developers can be notified when Advanced Protection is enabled so that they can auto-enable any features they have for this user population," Google said. "If you already use Advanced Protection, you will see a notification once these new capabilities arrive on your device. To take advantage of the new forensic capabilities, navigate to your Advanced Protection settings page and manually enable Intrusion Logging." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Android, Application Security, Malware, mobile security, Spyware ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header

Entities

Android 17 (product)Google (vendor)AccessibilityService API (technology)