Android 17 Clamps Down on Accessibility Service Abuse Used in Banking Malware
Google has announced that Android 17 will restrict access to the Accessibility Services API when Advanced Protection is enabled, limiting it to verified apps classified as genuine Accessibility Tools. Advanced Protection is a setting that turns on all of Android's security defences to help protect devices from threats.
The Accessibility Services API is designed to help users with disabilities, powering tools like screen readers and voice control. However, it gives apps powerful access to read what's on screen and act on a user's behalf, access that malicious apps have repeatedly abused. Once a user is tricked into enabling the service, often through social engineering, attackers can use it to steal sensitive data, log keystrokes, overlay fake login screens, initiate fraudulent transfers from banking apps, and even block the malware's own removal.
By restricting accessibility access to verified tools when Advanced Protection is active, Google aims to shut down this attack pathway while still supporting legitimate assistive technology. Android 17 will also notify developers when a user has Advanced Protection enabled, and introduces new forensic logging features that users can switch on manually from their settings.