Threat Intelligence

Android 17 Clamps Down on Accessibility Service Abuse Used in Banking Malware

The Hacker News · 2 Oct 2026
Key Takeaway Australian small businesses issuing or managing Android devices should enable Advanced Protection and train staff to never grant accessibility permissions to unfamiliar apps.

Google has announced that Android 17 will restrict access to the Accessibility Services API when Advanced Protection is enabled, limiting it to verified apps classified as genuine Accessibility Tools. Advanced Protection is a setting that turns on all of Android's security defences to help protect devices from threats.

The Accessibility Services API is designed to help users with disabilities, powering tools like screen readers and voice control. However, it gives apps powerful access to read what's on screen and act on a user's behalf, access that malicious apps have repeatedly abused. Once a user is tricked into enabling the service, often through social engineering, attackers can use it to steal sensitive data, log keystrokes, overlay fake login screens, initiate fraudulent transfers from banking apps, and even block the malware's own removal.

By restricting accessibility access to verified tools when Advanced Protection is active, Google aims to shut down this attack pathway while still supporting legitimate assistive technology. Android 17 will also notify developers when a user has Advanced Protection enabled, and introduces new forensic logging features that users can switch on manually from their settings.

Android security mobile malware accessibility services banking trojans Google

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.