Google announced Thursday that Android 17 will restrict access to the operating system's accessibility services, limiting them to verified applications categorized as Accessibility Tools when Advanced Protection is enabled. The tech giant said the measure blocks a primary attack route used by malicious Android apps, which have exploited the accessibility API to conduct malware infections and financial fraud. The move preserves assistive technology for users with disabilities while closing off what Google describes as a major avenue of attack.
The Android AccessibilityService API is a framework that permits an app to operate in the background, capture user interface events, and engage with other apps on behalf of the user. While designed to help users with disabilities through features like screen readers or voice control, its privileged access has been misused by banking trojans and spyware to steal sensitive information and carry out harmful actions without requiring root access. Once users are deceived into activating the service through social engineering tactics, malware can weaponize genuine assistive capabilities to initiate fraudulent fund transfers from installed financial apps, capture keystrokes, overlay fake login screens on legitimate apps, and grant itself additional sensitive permissions. Google noted that because accessibility services interact directly with the screen, bad actors can exploit them to read sensitive data, install malware, or prevent uninstallation.
According to Google, the company has implemented several steps in recent years to counter this abuse. These include blocking sideloaded apps from enabling accessibility services, in-call protections that stop users from disabling Google Play Protect or granting accessibility permissions, and setting the accessibilityDataSensitive flag to allow app developers to mark views as containing sensitive data. The company has also used Android Advanced Protection Mode to prevent certain types of apps from using the accessibility services API. Alongside the AccessibilityService API protection, Android 17 introduces Intrusion Logging for forensic investigation of sophisticated spyware attacks, USB Protection to prevent unauthorized access through physical USB connections, WebGPU disabling to reduce exposure to browser-based exploits, and Failed Authentication Lock to protect against physical tampering and brute-force attempts.
The accessibility API has become a preferred tool for cybercriminals precisely because it offers extensive control without needing to root the device, making attacks easier to execute at scale. By restricting which apps can use these powerful features when Advanced Protection is active, Google aims to create a protected tier for users who face elevated threats while maintaining functionality for legitimate assistive technologies that have passed verification. Developers can be notified when Advanced Protection is enabled so they can automatically activate any features they've built for this user population, and users who already use Advanced Protection will see a notification once these new capabilities arrive on their devices. To take advantage of the new forensic capabilities, users can navigate to their Advanced Protection settings page and manually enable Intrusion Logging.
The tiered approach reflects a broader industry challenge: balancing powerful developer tools with user safety in an ecosystem where malware authors constantly adapt to new defenses. Organizations managing Android fleets will need to weigh the trade-offs between enhanced security and potential workflow disruptions as employees adjust to more restrictive permissions.

