GOOGLE has announced Android 17 will tighten access to the Accessibility Services API by allowing only verified applications classified as Accessibility Tools to interact with the feature when Advanced Protection is turned on. The aim is to shut down a major attack pathway used by banking trojans and spyware that abuse accessibility permissions to read data, inject overlays, or automate fraudulent actions.
The company emphasised that, while assistive technology remains available, untrusted apps will no longer be able to leverage accessibility features to operate in the background or interact with other apps.
The change is part of a broader set of protections in the Android 17 release, designed to curb abuse of highly privileged accessibility access. In addition to restricting which apps can use the API, Google highlighted measures such as in‑call protections to stop users from disabling Play Protect, and the new accessibilityDataSensitive flag to mark views containing sensitive data as off‑limits to potentially malicious apps.
Android 17 also introduces Intrusion Logging for forensics, USB protection, and other hardening features, with a design intent to preserve essential assistive functionality while restricting abuse vectors.
Practically, users enrolled in Advanced Protection will receive this restriction automatically, and developers can expect to be notified when the feature is active so they can auto‑enable corresponding capabilities for protected users. For those relying on Advanced Protection, enabling Intrusion Logging via the settings page provides enhanced visibility for potential spyware activity.