Android 17 Restricts Accessibility API to Verified Tools Under Advanced Protection
Google has rolled out a new restriction in Android 17 that, once Android's Advanced Protection Mode (AAPM) is enabled, limits access to the AccessibilityService API exclusively to applications verified and classified as Accessibility Tools. The change, detailed in a Google Security Blog post published October 1, 2026 and reported by The Hacker News on October 2, 2026, directly targets one of the most heavily abused APIs in the Android malware ecosystem — the same framework banking trojans and spyware have long hijacked to read screen content, log keystrokes, and push through fraudulent transactions. The accessibility lockdown ships alongside five other new AAPM hardening features, including persistent intrusion logging, USB data-connection blocking, and the removal of WebGPU from Chrome.
Details
| Attribute | Value |
|---|---|
| Affected platform | Android 17 |
| Feature | Advanced Protection Mode (AAPM) |
| Mechanism | AccessibilityService access restricted to apps flagged isAccessibilityTool="true" and verified by Google |
| Activation | AAPM itself is opt-in (single toggle in Settings); the accessibility restriction applies automatically once AAPM is on — no separate switch |
| Companion features | Intrusion Logging, USB Protection, WebGPU disabled in Chrome, Failed Authentication Lock, "View Supporting Apps" transparency page |
| Availability | Core protections ship on all Android 17 devices; USB Protection and Failed Authentication Lock are limited to Pixel 6 and later, plus select Android 17 devices |
| Announced | October 1, 2026 (Google Security Blog) |
| Reported | October 2, 2026 (The Hacker News, Security Affairs, Help Net Security) |
Why the Accessibility API Is a Malware Favorite
The AccessibilityService API lets an app run in the background, read on-screen content, intercept UI events, and act on the user's behalf inside other apps — capabilities built for screen readers, voice-control tools, and Braille-display software. Google described the risk plainly in its announcement: "Because accessibility services are designed to interact directly with the screen, malicious actors can exploit them to read sensitive data, install malware, or block uninstallation." The company further noted that "applications abusing the AccessibilityService API remain a primary vector for attackers executing fraud and scams."
The abuse pattern is well established across years of mobile-malware reporting: a malicious app social-engineers a victim into granting accessibility permissions under a false pretext, then uses that access to silently read what's on screen (including one-time passcodes and banking balances), log keystrokes, overlay fake login screens on top of legitimate banking apps, auto-click through subsequent permission prompts, and even block the victim from uninstalling the app. Because none of this requires root access, accessibility abuse has become a cornerstone technique for Android banking trojans and commercial spyware alike.
How the New Restriction Works
With AAPM enabled on Android 17, the operating system automatically limits AccessibilityService access to apps that are both verified by Google and explicitly declared as accessibility tools — identified via the isAccessibilityTool="true" metadata flag that legitimate screen readers, voice-input tools, and similar assistive apps already carry. Any app that is not classified this way loses the ability to register an accessibility service while Advanced Protection is active, cutting off the permission-abuse pathway without disabling assistive technology for users who rely on it. Google frames the design as "closing off a major avenue of attack while preserving vital assistive technology" rather than a blanket ban on the API.
Part of a Broader Advanced Protection Hardening Push
The accessibility restriction is one of six protections Google bundled into this AAPM update. Intrusion Logging — described by Google as a mobile-industry first — provides end-to-end-encrypted forensic logs of security, network, and app activity, retained for 12 months to support spyware-targeting investigations; it requires a separate manual opt-in from the Advanced Protection settings page. USB Protection blocks new data connections while a device is locked (charging still works), defending against juice-jacking-style attacks via malicious cables or kiosks, but is currently limited to Pixel 6 and newer plus select Android 17 devices. WebGPU is disabled in Chrome under AAPM to shrink the browser's exploit surface, and a new Failed Authentication Lock locks the device after repeated failed unlock attempts on select hardware. A "View Supporting Apps" page gives users transparency into which installed apps actively check the new AdvancedProtectionManager API and adapt their own security posture when AAPM is detected.
Impact Assessment
| Impact Area | Description |
|---|---|
| Banking trojans and overlay malware | Loses its primary permission-abuse pathway on devices running Android 17 with AAPM enabled, since unverified apps can no longer register accessibility services |
| Legitimate assistive technology | Unaffected in intended operation — verified screen readers, voice-control, and Braille apps retain full accessibility access |
| User adoption | Protection only applies to users who manually enable AAPM; devices left in default configuration remain exposed to accessibility-based malware exactly as before |
| Developers of accessibility apps | Must ensure isAccessibilityTool="true" is declared and pass Google's verification, or their legitimate app will be locked out under AAPM |
| Enterprise mobile fleets | MDM-deployed assistive or remote-support tools that rely on accessibility services need verification review before AAPM is mandated fleet-wide |
| Spyware investigations | Intrusion Logging gives victims and researchers a new forensic trail, shipped as a companion feature to the accessibility lockdown |
Recommendations
For Everyday Android Users
- Enable Advanced Protection Mode in Settings if your device supports Android 17 — it is free, opt-in, and bundles the accessibility lockdown with USB and browser hardening in a single toggle.
- Be suspicious of any app that requests accessibility permissions outside of known screen-reader, voice-control, or Braille-display use cases; this remains the most common social-engineering lure for banking trojans.
- Review currently granted accessibility permissions in Settings → Accessibility and revoke access for any app that does not clearly need it, regardless of whether AAPM is enabled.
For Enterprise Mobile Device Management (MDM) Admins
- Inventory which managed apps (remote support tools, kiosk software, accessibility aids) depend on the AccessibilityService API before pushing AAPM as a mandatory profile across a fleet, since unverified internal or line-of-business tools could lose functionality.
- Coordinate with vendors of any accessibility-dependent enterprise app to confirm they carry the
isAccessibilityTool="true"flag and have completed Google's verification process. - Use the new Intrusion Logging capability where available to strengthen incident-response visibility on high-risk executive or field devices.
For Developers of Legitimate Accessibility Tools
- Declare
isAccessibilityTool="true"in your service metadata and complete Google's app verification well ahead of broader AAPM adoption to avoid users losing functionality when they enable Advanced Protection. - Use the
AdvancedProtectionManagerAPI to detect when AAPM is active and surface in-app guidance if your accessibility features would otherwise be restricted. - Audit your own accessibility usage against Google Play's policies now, since verification scrutiny on this API is likely to increase as more malware authors look for alternate abuse paths.
Key Takeaways
- Android 17's Advanced Protection Mode now restricts the AccessibilityService API to apps verified by Google and flagged
isAccessibilityTool="true". - The restriction applies automatically once AAPM is turned on — AAPM itself is opt-in, but the accessibility lockdown is not a separate toggle within it.
- The Accessibility API has long been abused by banking trojans and spyware to read screen content, log keystrokes, draw fake overlay logins, and block uninstallation, all without root access.
- The change ships alongside five other AAPM protections: Intrusion Logging, USB Protection, WebGPU removal in Chrome, Failed Authentication Lock, and a "View Supporting Apps" transparency page.
- USB Protection and Failed Authentication Lock are currently limited to Pixel 6+ and select Android 17 devices; the accessibility restriction and other core protections apply across Android 17 broadly.
- Legitimate assistive technology — screen readers, voice input, Braille tools — is designed to keep working under the restriction as long as it is verified; the gap it closes is for unverified apps abusing the same permission.
Sources
- Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools — The Hacker News
- 6 ways Advanced Protection on Android keeps you safe — Google Security Blog
- Android 17 makes it harder for spyware to cover its tracks — Help Net Security
- Advanced Protection Mode in Android 17 prevents apps from misusing Accessibility Services — Security Affairs