Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse

Ravie LakshmananMar 16, 2026Mobile Security / Data Protection

Android Accessibility API Security

Google is testing a new security feature as part of Android Advanced Protection Mode (AAPM) that prevents certain kinds of apps from using the accessibility services API.

The change, incorporated in Android 17 Beta 2, was first reported by Android Authority last week.

AAPM was introduced by Google in Android 16, released last year. When enabled, it causes the device to enter a heightened security state to guard against sophisticated cyber attacks. Like Apple’s Lockdown Mode, the opt-in feature prioritizes security at the cost of diminished functionality and usability so as to minimize the attack surface.

Cybersecurity

Some of the core configurations include blocking app installation from unknown sources, restricting USB data signaling, and mandating Google Play Protect scanning.

“Developers can integrate with this feature using the AdvancedProtectionManager API to detect the mode’s status, enabling applications to automatically adopt a hardened security posture or restrict high-risk functionality when a user has opted in,” Google noted in its documentation outlining Android 17’s features.

The latest restriction added to the one-tap security setting aims to prevent apps that are not classified as accessibility tools from being able to leverage the operating system’s accessibility services API. Verified accessibility tools, identified by the isAccessibilityTool=”true” flag, are exempted from this rule.

According to Google, only screen readers, switch-based input systems, voice-based input tools, and Braille-based access programs are designated as accessibility tools. Antivirus software, automation tools, assistants, monitoring apps, cleaners, password managers, and launchers do not fall under this category.

While AccessibilityService has its legitimate use cases, such as assisting users with disabilities in using Android devices and apps, the API has been extensively abused by bad actors in recent years to steal sensitive data from compromised Android devices.

Cybersecurity

With the latest change, any non-accessibility app that already has the permission will have its privileges automatically revoked when AAPM is active. Users will also not be able to grant apps permissions to the API unless the setting is turned off.

Android 17 also comes with a new contacts picker that allows app developers to specify only the fields they want to access from a user’s contact list (e.g., phone numbers or email addresses) or allow users to select certain contacts with a third-party app.

“This grants your app read access to only the selected data, ensuring granular control while providing a consistent user experience with built-in search, profile switching, and multi-selection capabilities without having to build or maintain the UI,” Google said.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Chinese Payment Apps Raise Concerns of a Parallel Economy in Japan

Finance Minister Satsuki Katayama said on March 11 that the spread of Chinese smartphone payment apps in Japan, and the emergence of communities operating outside Japan’s legal and regulatory framework, posed “a serious issue.” She said Japan would work with the G7 nations, including the United States and European partners, to address it. Katayama made

Psycholology says people who plan their days in writing and people who use phone apps aren’t just using different tools — they’re processing their entire sense of direction differently

Add VegOut to your Google News feed. You know that feeling when you watch someone pull out a leather-bound planner in a coffee shop while you’re frantically swiping through your calendar app? There’s something almost ritualistic about the way they write, crossing things off with actual ink. Meanwhile, you’re juggling three productivity apps, color-coded notifications,

Ukraine’s anti-drone tech is in high demand as Iran attacks its neighbors

KYIV, Ukraine — As the conflict in the Middle East escalates, Ukraine could prove to be an invaluable trove of battle-tested expertise from its own bitter and costly fight against Russia. After months of pressure and hardened rhetoric from Washington aimed at ending the war in Ukraine, Kyiv is now also fielding requests for help

Google app starts rolling out quick access to AI Mode history

The Google app on Android is rolling out convenient, persistent access to AI Mode history for a more integrated experience. In the Home tab (Discover feed), Google has replaced the Labs beaker with a button for AI Mode history, which recently switched from a circle to this lined version. Tapping slides over your recent chats

I tried replacing all my paid Windows apps with open-source alternatives

I’ve spent the last few years slowly moving away from corporate software and switching to free and open-source alternatives. I have fully switched to Linux as my main desktop. I set up a little home server to cut subscriptions and host open-source apps. When I do use Windows, I make an effort to find FOSS

Seedance 2.0 暫停全球推出,字節跳動捲版權爭議後 AI 影片工具出海受阻

Seedance 2.0 暫停全球推出,字節跳動捲版權爭議後 AI 影片工具出海受阻 字節跳動旗下新版 AI 影片生成模型 Seedance 2.0 原計劃在 3 月中向海外市場擴大推出,但現在公司被傳已按下暫停鍵。根據 The Information 引述知情人士的說法,字節已叫停該工具的全球上線計劃,現階段正處理與版權相關的法律問題。 這次延期與 Seedance 2.0 推出後迅速引發的荷里活版權爭議有直接關係,路透指出,字節跳動的法務團隊正著手識別及解決潛在法律風險,而工程團隊也在為模型加入更多防護措施,以避免系統再生成可能引發 IP 爭議的內容。​ 爭議從中國版推出後迅速升溫 Seedance 2.0 於 2 月在中國正式亮相後,很快就因高擬真影片生成能力引起關注。平台上曾出現包括 Brad Pitt 與 Tom Cruise 打鬥等 AI 影片,令外界質疑模型是否曾使用受版權保護角色、作品或名人形象作訓練或生成依據。 這些影片在社交平台迅速擴散,也讓 Seedance 2.0 在短時間內成為荷里活關注焦點。迪士尼其後向字節發出停止侵權通知,指 Seedance 使用迪士尼角色訓練及驅動模型,並形容系統像是內建一個「被盜版角色庫」,涉及漫威與《星戰》等作品角色。 不只迪士尼,其他片商也出手 除了迪士尼外,派拉蒙天空之舞也已向字節跳動發出停止侵權通知。Variety 報道指,派拉蒙在法律文件中指控 Seedance 涉及 IP 侵權問題,並點名《南方四賤客》、《星艦迷航記》與《教父》等作品內容。​ BBC 早前報道亦提到,Motion Picture Association 已要求 Seedance

Tariffs Just Helped Push Kia’s Hottest EV Off the U.S. Market

In today’s auto industry, few political and economic tools carry as much impact as tariffs. Their consequences for the automotive sector in the United States are hard to overstate. Automakers and suppliers are facing billions of dollars in additional costs, forcing companies to reorganize and fragment global supply chains while production expenses continue to rise.

5 Handy Tools Your Phone Turned Into Apps

Rouzes/Getty Images In the early days of smartphones, when Apple first launched the App Store a year later, the slogan “There’s an app for that” proved to be an incredibly effective campaign that signaled iOS has an app for everything. These days, Android is the king of mobile

AI is helping choose targets in Iran war — now it’s a target too

This Amazon data centre sits on the outskirts of Abu Dhabi, directly across the water from the Iranian coast. An Amazon data centre in the United Arab Emirates.(Google, Airbus) Stocked with high-powered computers that run day and night, this structure is where “the cloud” takes on physical form. Amazon has six data centres across Bahrain

Indie App Spotlight: ‘Kiosk 27’ makes your iPhone camera feel like film

Welcome to Indie App Spotlight. This is a weekly 9to5Mac series where we showcase the latest apps in the indie app world. If you’re a developer and would like your app featured, get in contact. iPhone cameras have come a long way over the years, but if you find yourself yearning for more of a classy, filmic

Burglars steal cash, jewellery & mobile phones | Chandigarh News

Times News NetworkChandigarh: Burglars broke into houses and offices in different parts of the city and decamped with gold and silver jewellery, mobile phones, cash, and other valuables. The complainant, Rohit Kumar, a resident of Dadumajra Colony, Sector 38, said he went to his mother’s house in Sector 56 on March 12. When he returned

As people look for ways to make new friends, here are the apps promising to help

In recent years, people have been increasingly looking for new ways to form platonic connections, as loneliness and social isolation have become more prevalent. In 2023, the U.S. Surgeon General went so far as to label this issue a public health crisis. Remote workers, who miss the everyday interactions found in an office, and younger

RedMagic 11 Air review: performance over prettiness

Why you can trust TechRadar We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test. RedMagic 11 Air: Two-minute review Like its lightweight predecessor, the RedMagic 10 Air, the RedMagic 11 Air represents a smart piece of repurposing. It

0
Would love your thoughts, please comment.x
()
x