Google has released Android 17, publishing the source code to AOSP under the tag android-17.0.0_r1 and beginning rollout to supported Pixel devices, with broader availability planned across OEMs including HONOR, Lenovo, OnePlus, OPPO, vivo, Xiaomi, and others. Google also made Generic System Images available for ARM64 and x86_64, while the platform adds major usability and device features such as foldable enhancements, App Bubbles, Handoff support, VVC/H.266 video, RAW14, HE-AAC, BLE hearing-aid improvements, and OpenJDK 25 integration.
The release introduces a broad set of security and privacy changes, including tighter controls for contacts, location, and local network access, expanded one-time-password handling beyond SMS, stricter restrictions on dynamic code loading, stronger lost-device protections, improved threat detection, enhanced Advanced Protection, and stricter PIN retry limits. Google also added Certificate Transparency-related enhancements, support for HPKE cryptography and ML-DSA APK signatures, and continued restrictions on cleartext traffic, alongside Pixel-specific updates delivered through the June Pixel Drop.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Google announced Android 17 alongside the June 2026 Pixel Drop, with rollout starting on Pixel devices first and broader Android device availability planned throughout 2026. The update introduced new usability features and security changes including tighter permissions, stronger lost-device protections, improved threat detection, enhanced Advanced Protection, and stricter PIN retry limits.
Google announced Android 17 and published its source code in the Android Open Source Project repository under the tag android-17.0.0_r1. The release was made available for supported Pixel devices, with factory images and GSI images for ARM64 and x86_64 also published.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
33 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcesecurityonline.info
Open sourcehelpnetsecurity.com
Open sourceghacks.net
Open sourcedeveloper.android.com
Open sourcedeveloper.android.com
Open sourcedeveloper.android.com
Open sourcedeveloper.android.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.