Google said Android 17 will begin a broad migration to post-quantum cryptography as part of a plan to harden the platform against future quantum attacks on public-key systems. The company is introducing quantum-resistant protections across core trust components, including Android Verified Boot, Remote Attestation, KeyMint, and Android Keystore, with support centered on the NIST-standardized ML-DSA algorithm. Google said the move is intended to build a quantum-resistant chain of trust spanning device boot, identity verification, and hardware-backed security services.
Google also said Google Play will support hybrid app signing that combines classical and post-quantum signatures, and will begin generating quantum-safe ML-DSA signing keys for new apps while allowing existing apps to opt in. The company is targeting completion of its broader post-quantum migration by 2029, citing the risk of store-now-decrypt-later attacks and warning that organizations should begin adopting NIST-developed PQC standards before fault-tolerant quantum computers can break current encryption. Google added that future Play updates are expected to support hybrid key upgrades and prompt developers to rotate signing keys every two years.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Google said Google Play will support quantum-safe app signing by generating ML-DSA signing keys for new apps and opt-in existing apps, alongside hybrid signing support that combines classical and post-quantum signatures for APK authenticity and updates.
Google announced that Android 17 will begin a broad migration to post-quantum cryptography, introducing ML-DSA-based protections for Android Verified Boot, Remote Attestation, KeyMint, and Android Keystore as the first phase of a longer-term quantum-resistant chain of trust.
Google said it is preparing for the quantum era and aims to complete its post-quantum cryptography migration by 2029, citing risks such as store-now-decrypt-later attacks and updating its threat model to prioritize PQC for authentication services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcescworld.com
Open sourceschneier.com
Open sourcehackread.com
Open sourceitpro.com
Open sourcedarkreading.com
Open sourceitsecurityguru.org
Open sourcehelpnetsecurity.com
Open sourcesecurity.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.