Google is adding six security capabilities to Android 17’s Advanced Protection suite to make targeted compromise and spyware activity harder to conceal. The most significant addition, Intrusion Logging, records security, network, and app-activity events in tamper-resistant encrypted logs, retains them in Google cloud storage for up to 12 months, and lets users decrypt and share evidence with trusted security experts.
The expanded protections also block USB data connections while a device is locked, restrict unverified AccessibilityService applications, disable Chrome WebGPU, and incorporate Failed Authentication Lock. The controls are designed to reduce exposure to physical-access attacks, fraud, malicious accessibility-service abuse, and sophisticated browser exploitation; feature availability will vary by Android device.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Google added six security capabilities to Android 17 Advanced Protection, including optional Intrusion Logging, USB data-connection protection while locked, accessibility-service restrictions, Chrome WebGPU disabling, and Failed Authentication Lock on selected devices. Availability varies by device, and existing Advanced Protection users will be notified as capabilities become available.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.