Android 17 Advanced Protection brings a critical change to the way Accessibility Services are managed : from now on, when Advanced Protection is enabled , access to the AccessibilityService API is limited exclusively to verified apps categorized as Accessibility Tools . Google announced this move as a direct response to the widespread abuse of this API by malicious apps, banking trojans, and spyware that affect millions of Android users worldwide.

Android ’s AccessibilityService API is a powerful framework that allows an app to run in the background, listen for UI events, and interact with other apps on behalf of the user. While its primary purpose is to help users with disabilities — through screen readers, voice control systems, and other assistive technologies — the privileged access it provides has long been a target for malicious actors to exploit. The problem is so severe that Google calls it a “ primary attack vector ” for malware and financial fraud .
When a user is tricked — through social engineering — into activating a malicious Accessibility Service, the malware gains the ability to perform a series of extremely dangerous actions: automatically initiate fraudulent money transfers from installed financial applications, record keystrokes (keylogging), display fake login screens on top of legitimate applications (overlay attacks), and grant itself additional sensitive permissions — all without requiring root access.
See also: Chrome Android: New details about Advanced Protection
Android 17 Advanced Protection: How the new protection works
With Android 17, enabling Advanced Protection automatically restricts access to AccessibilityService only to verified apps that are categorized as Accessibility Tools. This means that any app that doesn't meet these criteria — even if the user tries to grant it permission — won't be able to use the API.
This move isn't Google 's first attempt to address the abuse of Accessibility Services. In recent years, the company has taken a number of measures: blocking apps installed outside of Google Play ( sideloaded apps ) from enabling accessibility services, protections during calls that prevent users from disabling Google Play Protect or granting accessibility permissions, and the introduction of the flag accessibilityDataSensitive that allows developers to mark sensitive data so that it can't be accessed by malicious apps.

The new approach with Android 17 Advanced Protection is more radical: instead of trying to detect malicious behavior after the fact, it blocks any unverified app from accessing the API in the first place. This “zero-trust” approach represents a significant evolution in Google’s security strategy for Android.
Android 17 Advanced Protection: All new security features
Alongside the Accessibility Services protection, Android 17 brings a number of other important security improvements. Intrusion Logging enables persistent, privacy-preserving logging for forensic analysis, particularly useful for investigating sophisticated spyware. This feature must be manually enabled from the Advanced Protection settings and is primarily aimed at high-risk users such as journalists, activists and business executives.
See also: How to enable Advanced Data Protection for iCloud (+ end-to-end encryption)
USB Protection prevents attackers from gaining unauthorized access to the device via a physical USB — a technique known as juice jacking or USB-based exploitation. Disabling WebGPU reduces exposure to sophisticated browser-based exploits, while Failed Authentication Lock completely locks the device after repeated failed authentication attempts, protecting against brute-force attacks and physical tampering. Finally, the View Supporting Apps allows users to see which installed applications have checked the status of Advanced Protection.
It’s worth noting that Advanced Protection isn’t new to Android — it’s already existed as a feature that enables all of the device’s security features. However, with Android 17, Google is significantly expanding its capabilities, essentially making it a comprehensive “shield” against the most advanced threats. Users who have already enabled Advanced Protection will receive a notification when the new features arrive on their device.

For app developers, Google is providing the ability to receive a notification when a user turns on Advanced Protection, so they can automatically enable any additional security features they have for that user category. This creates an ecosystem where security is strengthened at multiple levels — both from the operating system side and from the apps themselves.
See also: Android Intrusion Logging: New Spyware Detection Feature
The threat from the misuse of Accessibility Services is particularly serious in Greece and Europe, where banking trojan such as Anatsa, Medusa , and TrickMo have targeted Android users with the aim of stealing banking credentials and performing unauthorized transactions. These malware use exactly the techniques that Android 17 Advanced Protection aims to block: overlay attacks, keylogging, and automatic execution of actions via Accessibility Services.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
According to The Hacker News, Google emphasizes that “because accessibility services are designed to interact directly with the screen, malicious actors can exploit them to read sensitive data, install malware , or block uninstallation.” This admission from Google itself underscores the magnitude of the problem and the necessity of the new measures.
