Google Blocks Accessibility API Abuse in Android 17 to Enhance Security

Google Blocks Accessibility API Abuse in Android 17 to Enhance Security

First seen 16 Mar 2026, 10:52 UTC Heise.DeSecurityaffairs.CoGbhackersCybersecuritynewsFeeds2.Feedburner 57.6

Article Content

Browse articles
ThreatCluster

Google is implementing significant security measures in Android 17, particularly through the Advanced Protection Mode (AAPM), which restricts access to the Accessibility API for non-accessibility apps. This change aims to mitigate the misuse of the API, which has been exploited by malware such as the Anatsa banking trojan and Copybara malware to steal sensitive user information. Users will encounter a block message stating 'Restricted by Advanced Protection Program' when attempting to activate the AccessibilityService API for unauthorized apps. While legitimate apps like screen readers and password managers can still function, automation and customization apps may become inoperable under this new restriction. Google has previously warned developers against misusing the API but has not enforced strict measures until now. The update is part of a broader initiative to enhance device security and user privacy in Android 17, which is currently in beta testing. The rollout of these features is expected to significantly reduce the risk of malware exploiting the Accessibility API.

Key Points: • Android 17 introduces Advanced Protection Mode to block unauthorized access to the Accessibility API. • Malware like Anatsa and Copybara has exploited the Accessibility API for data theft. • Users can disable the Advanced Protection Program but at the cost of their security.

Timeline

2026-03-14
Google releases Android 17 Beta 2 with new security features.
2026-03-16
Articles published detailing the Advanced Protection Mode in Android 17.