Application Security · Credential Theft

Android 17 Locks Down Spyware Traces

Google added two notable security changes in Android 17 for Advanced Protection: intrusion logging that can keep security and network evidence off the handset for up to 12 months, and a tighter rule that limits AccessibilityService access to verified Accessibility Tools. Google says the logs are end-to-end encrypted, stored on its servers, and optional.

The logging system records device and network activity, then lets the owner decrypt and share it later, so a wipe or account closure does not immediately erase the trail. At the same time, blocking unverified apps from accessibility access cuts off a common route used by banking trojans and spyware to read screens, intercept input, and act without root.

For mobile investigators and teams supporting high-risk users, the shift is that useful evidence may now live in cloud-retained logs rather than on the phone itself. It also means some Android spyware will lose one of its easiest abuse paths, while the remaining forensic questions move toward who enabled logging and whether the preserved records were available before the incident ended.

2 sources · 6h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-02

Every edition of this story: Android 17 Locks Down Spyware Traces