Securityaffairs.Co Google Blocks Accessibility API Abuse in Android 17 to Enhance Security
Article Content
- •Android 17 introduces Advanced Protection Mode to block unauthorized access to the Accessibility API.
- •Malware like Anatsa and Copybara has exploited the Accessibility API for data theft.
- •Users can disable the Advanced Protection Program but at the cost of their security.
Google is implementing significant security measures in Android 17, particularly through the Advanced Protection Mode (AAPM), which restricts access to the Accessibility API for non-accessibility apps. This change aims to mitigate the misuse of the API, which has been exploited by malware such as the Anatsa banking trojan and Copybara malware to steal sensitive user information. Users will encounter a block message stating 'Restricted by Advanced Protection Program' when attempting to activate the AccessibilityService API for unauthorized apps. While legitimate apps like screen readers and password managers can still function, automation and customization apps may become inoperable under this new restriction. Google has previously warned developers against misusing the API but has not enforced strict measures until now. The update is part of a broader initiative to enhance device security and user privacy in Android 17, which is currently in beta testing. The rollout of these features is expected to significantly reduce the risk of malware exploiting the Accessibility API.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Anatsa Banking Trojan in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…