Google released Android 17 QPR2 Beta 3 for supported Pixel devices, adding a new app-lock feature, broader interface customization, and several security changes. The update lets users require fingerprint or PIN re-authentication to open protected apps, expands theming and Quick Settings layout controls, and fixes bugs tied to notification and Quick Settings interactions that could trigger display problems or unexpected restarts, along with false battery-capacity warnings in device diagnostics.
The most significant security change targets call-forwarding scams by restricting apps from silently sending call-forwarding USSD codes through TelephonyManager.sendUssdRequest() with only the CALL_PHONE permission, while also adding an OS-level confirmation dialog when users manually enter call-forwarding codes in the system dialer. Google also expanded Mobile Network Security visibility with a timestamped SIM security timeline and details on cellular encryption ciphers, with signs that future alerts may cover downgrade, denial-of-service, jamming, and location-tracking threats.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Google had previously introduced expanded theming controls, including additional color styles and a broader color-selection slider, in the Android Canary channel. These customization options were later included in Android 17 QPR2 Beta 3.
An app-lock feature requiring fingerprint or PIN re-authentication to open protected apps appeared in an Android Canary build before being removed and later reintroduced in Android 17 QPR2 Beta 3.
Google fixed a bug in Android 17 QPR2 Beta 3 that caused display issues and unexpected restarts when opening notifications and Quick Settings. The release also resolved false reduced-battery-capacity warnings in the Device Diagnostics and Support tool.
Android 17 QPR2 Beta 3 expanded Mobile Network Security with a timestamped SIM security timeline and visibility into cellular encryption ciphers. Strings in the beta also indicated Google was preparing warnings for downgrade, denial-of-service, jamming, and location-tracking attacks.
Google added restrictions on call-forwarding USSD codes executed through TelephonyManager.sendUssdRequest(), blocking standard apps from silently running those codes in the background with only the CALL_PHONE permission and returning USSD_ERROR_NOT_ALLOWED for blocked attempts. Android also began showing an OS-level confirmation dialog when users manually enter call-forwarding codes in the system dialer.
Google released Android 17 QPR2 Beta 3 to supported Pixel devices, distributing build CP41.260731.005.A2 to Pixel 6a, Pixel 7 series, Pixel 7a, Pixel Fold, and Pixel Tablet, and build CP41.260731.005.B1 to other eligible models. The beta added interface customization changes, bug fixes, and security updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.