HomeSecurityAndroid 17 blocks non-accessibility apps from the API

Android 17 blocks non-accessibility apps from the API

Google is testing a new security feature in Android 17 that blocks certain apps from using the AccessibilityService API , aiming to prevent malware from exploiting it. The change, which was introduced in Android 17 Beta 2 , is part of Android Advanced Protection Mode (AAPM) and was first reported by Android Authority last week. The move represents a radical shift in Google ’s approach to Android security , as the company acknowledges that the AccessibilityService API is actively being used by malicious actors.

Android 17 blocks non-accessibility apps from the API

AAPM was introduced by Google in Android 16 released in 2025, as an optional feature that mimics Apple 's Lockdown Mode . When enabled , AAPM puts the device in an increased security state to protect against sophisticated cyberattacks. The feature prioritizes security over functionality , reducing the attack surface through various restrictions. The philosophy behind this approach is that high-risk users, such as journalists, activists, and politicians, need an extra layer of protection that can be activated immediately when faced with threats.

Some of the basic AAPM settings include blocking app installation from unknown sources , restricting data transfer via USB , and requiring Google Play Protect scanning . Developers can implement this feature by using the AdvancedProtectionManager API to detect the mode state, allowing apps to automatically adopt an enhanced security posture. This means apps can automatically disable high-risk features or restrict access to sensitive data when AAPM is active.

See also: 6 new Android malware targets banking apps

New restrictions in Android 17 for AccessibilityService

Android 17 security AccessibilityService API restrictions

The latest restriction added in Android 17 aims to prevent apps that are not categorized as accessibility tools from leveraging the AccessibilityService API . Verified accessibility tools, identified by the isAccessibilityTool=”true”, are exempt from this rule. This change is particularly important because the AccessibilityService API provides extensive permissions that can be used to monitor all user activity on the device.

According to Google, only screen readers, switch-based input systems, voice input tools, and Braille qualify as accessibility tools. Antivirus programs, automation tools, assistants, monitoring applications, cleaners, password managers, and launchers do not fall into this category. This strict separation creates a clear line between legitimate accessibility tools and other applications that may abuse these features.

See also: Fake IPTV apps distribute Android malware Massiv

The AccessibilityService API has legitimate uses, such as helping users with disabilities use Android. However, the API has been extensively abused by malicious actors in recent years to steal sensitive data from infected Android. Malware such as Anatsa and SOVA exploited AccessibilityService for overlay attacks, stealing banking credentials via fake login screens. The Catwatchful spyware, detected in late 2025, used AccessibilityService to record keystrokes and screenshots, affecting over 100,000 users worldwide.

Automatic revocation of rights and new features

With the latest change in Android 17, any non-accessibility apps that are already in use will automatically lose their privileges when AAPM is active. Users will also not be able to grant apps API permissions unless the setting is disabled. This restriction addresses a long-standing abuse of AccessibilityService by malware that used accessibility to track interactions and perform automated actions. Automatic revocation is especially important because many users are unaware of which apps have such permissions or how they can be abused.

See also: BeatBanker: Android malware mimics Starlink app to compromise devices

PixRevolution Android malware targets Pix payment systems

Android 17 also comes with a new contacts picker that allows app developers to specify only the fields they want to access from a user’s contact list (e.g. phone numbers or email addresses) or allow users to select specific contacts with a third-party app. This gives the app read-only access to the selected data, ensuring granular control. This approach follows the principle of least privilege, where apps are only granted the access they need to function.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS