Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • Advanced Protection Mode in Android 17 prevents apps from misusing Accessibility Services Pierluigi Paganini
    Android 17 will block non-accessibility apps from using the Accessibility API under Advanced Protection Mode to reduce malware abuse. Android 17 introduces a new security feature in Advanced Protection Mode (AAPM) that blocks apps without accessibility functions from accessing the Accessibility API. The change, first reported by Android Authority and included in Android 17 Beta 2, aims to prevent malware from abusing these services to spy on users, steal data, or control devices. The Acce
     

Advanced Protection Mode in Android 17 prevents apps from misusing Accessibility Services

16 de Março de 2026, 07:34

Android 17 will block non-accessibility apps from using the Accessibility API under Advanced Protection Mode to reduce malware abuse.

Android 17 introduces a new security feature in Advanced Protection Mode (AAPM) that blocks apps without accessibility functions from accessing the Accessibility API. The change, first reported by Android Authority and included in Android 17 Beta 2, aims to prevent malware from abusing these services to spy on users, steal data, or control devices.

The AccessibilityService API allows apps to interact deeply with the Android interface to help people with disabilities navigate and control their devices. Apps designed for accessibility can declare the isAccessibilityTool attribute and are exempt from some disclosure requirements.

However, this powerful access has been abused by malware in the past. Malicious apps have used the API to read screen content, capture keystrokes, click buttons automatically, grant themselves permissions, and steal sensitive data such as banking credentials. Because it can control the interface, attackers have leveraged it to perform fraud, install additional malware, and bypass security prompts.

The new feature adds stricter security settings, including blocking app installs from unknown sources, limiting USB data access, and requiring Google Play Protect scans. The update also restricts use of the Accessibility Services API, allowing only verified accessibility tools marked with the isAccessibilityTool="true" flag. Developers can detect when the mode is enabled using the AdvancedProtectionManager API and adapt their apps with stronger security controls.

“Designed as an opt-in feature, AAPM is activated with a single configuration setting that users can turn on at any time to apply an opinionated set of security protections. These core configurations include blocking app installation from unknown sources (sideloading), restricting USB data signaling, and mandating Google Play Protect scanning, which significantly reduces the device’s attack surface area.” reads Google’s announcement. “Developers can integrate with this feature using the AdvancedProtectionManager API to detect the mode’s status, enabling applications to automatically adopt a hardened security posture or restrict high-risk functionality when a user has opted in.”

According to Google, only tools such as screen readers, switch-input systems, voice input tools, and Braille access apps qualify as accessibility tools. Other apps, like antivirus, automation tools, assistants, cleaners, password managers, and launchers, do not.

Android 17 also introduces a new contacts picker that lets apps request access only to specific contact fields, such as phone numbers or email addresses, or allows users to share selected contacts with third-party apps. According to Google, this feature improves privacy by limiting data access while offering built-in search, profile switching, and multi-selection without requiring developers to build their own interface.

“The Android Contact Picker is a standardized, browsable interface for users to share contacts with your app. Available on devices running Android 17 or higher, the picker offers a privacy-preserving alternative to the broad READ_CONTACTS permission. Instead of requesting access to the user’s entire address book, your app specifies the data fields it needs, such as phone numbers or email addresses, and the user selects specific contacts to share.”states Google. “This grants your app read access to only the selected data, ensuring granular control while providing a consistent user experience with built-in search, profile switching, and multi-selection capabilities without having to build or maintain the UI.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)

  • ✇Arstechnica
  • Google introduces Advanced Protection mode for its most at-risk Android users Dan Goodin
    Google is adding a new security setting to Android to provide an extra layer of resistance against attacks that infect devices, tap calls traveling through insecure carrier networks, and deliver scams through messaging services. On Tuesday, the company unveiled the Advanced Protection mode, most of which will be rolled out in the upcoming release of Android 16. The setting comes as mercenary malware sold by NSO Group and a cottage industry of other exploit sellers continues to thrive. These play
     

Google introduces Advanced Protection mode for its most at-risk Android users

13 de Maio de 2025, 17:31

Google is adding a new security setting to Android to provide an extra layer of resistance against attacks that infect devices, tap calls traveling through insecure carrier networks, and deliver scams through messaging services.

On Tuesday, the company unveiled the Advanced Protection mode, most of which will be rolled out in the upcoming release of Android 16. The setting comes as mercenary malware sold by NSO Group and a cottage industry of other exploit sellers continues to thrive. These players provide attacks-as-a-service through end-to-end platforms that exploit zero-day vulnerabilities on targeted devices, infect them with advanced spyware, and then capture contacts, message histories, locations, and other sensitive information. Over the past decade, phones running fully updated versions of Android and iOS have routinely been hacked through these services.

A core suite of enhanced security features

Advanced Protection is Google’s latest answer to this type of attack. By flipping a single button in device settings, users can enable a host of protections that can thwart some of the most common techniques used in sophisticated hacks. In some cases, the protections hamper performance and capabilities of the device, so Google is recommending the new mode mainly for journalists, elected officials, and other groups who are most often targeted or have the most to lose when infected.

Read full article

Comments

© Getty Images

❌
❌