Google has announced that Android 17 will restrict accessibility service access to verified applications when Advanced Protection is enabled. The move is designed to close a major attack pathway that malicious apps have used for malware distribution and financial fraud.

Accessibility services are intended to help users with disabilities, but they can also read screen content, log keystrokes, and interact with other apps. Attackers have abused this by tricking users into enabling malicious services, which can then steal credentials, draw fake login screens, and initiate fraudulent transfers.

The new restriction is part of a broader set of Android 17 security improvements, including intrusion logging, USB protection, a WebGPU disable option, and a failed authentication lock. Google also said developers can be notified when Advanced Protection is enabled, and existing users will see a notification once the new capabilities arrive on their devices.