Google added a new safeguard in Android 17 Beta 2 that blocks apps not classified as genuine accessibility tools from using the Accessibility Services API when Android Advanced Protection Mode (AAPM) is enabled. The change is intended to reduce a long-standing abuse path used by Android malware, which has leveraged accessibility permissions to read screen content, capture keystrokes, click through prompts, grant permissions, install additional payloads, and steal sensitive data including banking credentials. Under the new model, only verified accessibility apps marked with isAccessibilityTool="true" can retain this level of access.
The restriction expands AAPM’s opt-in hardened security posture, which already includes controls such as blocking installs from unknown sources, limiting USB data access, and requiring Google Play Protect scanning. Google said developers can use the AdvancedProtectionManager API to detect whether the mode is active and adjust application behavior accordingly. The policy also narrows which app categories qualify as accessibility tools, with examples including screen readers, switch-based input, voice input, and Braille access software, while categories such as antivirus tools, automation apps, assistants, monitoring apps, cleaners, password managers, and launchers are not treated as accessibility tools for this exemption.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
By March 19, reporting described the accessibility-service restrictions as applying in Android 17.2 when Advanced Protection Mode is enabled, including revoking or preventing access for categories such as password managers and automation tools.
Google also introduced a new Android contact picker in Android 17 that lets users share only selected contacts or specific contact fields with apps instead of granting broad contact-list access.
Alongside the accessibility restriction, Android 17's Advanced Protection Mode was described as blocking sideloading, restricting USB data signaling, requiring Google Play Protect scans, and exposing an AdvancedProtectionManager API so apps can adapt when the mode is enabled.
In Android 17 Beta 2, Google added a new Advanced Protection Mode control that blocks most non-accessibility apps from using Accessibility Services, while allowing verified accessibility tools marked for legitimate use.
For Android 12 and later, Google introduced permission declarations that required apps to justify accessibility service use, adding another control against abuse of the API.
Google had been incrementally addressing abuse of Android's Accessibility Services API since at least 2017 through Play Store policy enforcement aimed at limiting misuse by malware and other non-accessibility apps.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.