Skip to main content
CybersecurityHacking

Google Fortifies Android with Tougher Accessibility Service Controls

Smartphone settings menu on a living room table with assistive devices.

"In Android 17, enabling Advanced Protection automatically restricts AccessibilityService access exclusively to verified applications categorized as Accessibility Tools, closing off a major avenue of attack while preserving vital assistive technology," Google said Thursday.

What Google changed in Android 17

With Android 17, Google has tied a new restriction on the AccessibilityService API to Advanced Protection: when Advanced Protection is enabled, only verified applications that are explicitly categorized as Accessibility Tools may use AccessibilityService. Google framed this as a measure that both "closes off a major avenue of attack" and preserves assistive technology for users who need it.

The AccessibilityService API is a privileged framework that lets an app run in the background, intercept user interface events, and interact with other apps on the user's behalf. Although its primary purpose is to assist users with disabilities — for example via screen readers or voice control — Google said its high level of access has been abused by banking trojans and spyware to steal data and commit financial fraud.

How attackers have abused accessibility services

Google's advisory catalogs a set of concrete abuses that motivated the change: once a user is tricked into enabling an accessibility service, malware can use those legitimate assistive features to perform malicious actions without root access. The source lists specific capabilities abused by malware: programmatically initiating fraudulent fund transfers from installed financial apps, logging keystrokes, drawing fake login screens over legitimate apps, granting itself additional sensitive permissions, reading sensitive data, installing malware, or blocking uninstallation.

Other Android 17 security controls shipped alongside Accessibility protections

Android 17 bundles the AccessibilityService restriction with several other security improvements intended to harden devices against sophisticated remote and physical attacks:

  • Intrusion Logging — described as persistent, privacy-preserving forensics logging to investigate sophisticated spyware attacks. Google noted users must manually enable Intrusion Logging from the Advanced Protection settings page to take advantage of these forensic capabilities.
  • USB Protection — intended to prevent attackers from gaining unauthorized access to a device through a physical USB connection.
  • Disable WebGPU — a setting that reduces exposure to sophisticated browser-based exploits.
  • Failed Authentication Lock — a feature that locks down the device completely after authentication failures to protect against physical tampering and brute-force attempts.
  • View Supporting Apps — a capability that allows users to view which installed apps have checked the Advanced Protection status.

How developers and Accessibility Tool vendors are affected

Google said developers can be notified when Advanced Protection is enabled so they "can auto-enable any features they have for this user population." The new rule restricts AccessibilityService access to apps that are verified and categorized as Accessibility Tools; developers of assistive-technology apps will therefore need to ensure their apps meet whatever verification and categorization criteria Google applies in order to retain functionality for users in Advanced Protection.

What end users should look for and do

Google said users who already use Advanced Protection will see a notification once the new capabilities arrive on their device. To use the new forensic features, users must navigate to their Advanced Protection settings page and manually enable Intrusion Logging. The company also highlighted prior mitigations it has rolled out to counter accessibility abuse — blocking sideloaded apps from enabling accessibility services, in-call protections that prevent disabling Play Protect or granting accessibility permissions during calls, and the accessibilityDataSensitive flag for developers to mark sensitive views.

The practical balance Google is aiming for

Google's messaging frames the change as a targeted tightening: restrict a powerful API when the device is in its most protected state, while keeping assistive technologies functional. The company presented the restriction as part of a multi-year effort that already includes blocking sideloaded apps from enabling accessibility services, in-call protections, and developer controls such as accessibilityDataSensitive. Taken together, those steps form a layered approach — limiting who can access AccessibilityService under Advanced Protection while adding logging and hardware- and browser-focused protections in Android 17.

Users of Advanced Protection will receive a notification when these capabilities reach their devices; developers of assistive tools can expect a notification option to adapt features for Advanced Protection users; and Google has called out Intrusion Logging as a manually enabled setting for those who want forensic telemetry. The next factual milestone the company has identified is the appearance of that user notification and the manual activation of Intrusion Logging from the Advanced Protection settings page.

Source: The Hacker News