AppSec · 5h ago
Google added two notable security changes in Android 17 for Advanced Protection: intrusion logging that can keep security and network evidence off the handset for up to 12 months, and a tighter rule that limits AccessibilityService access to verified Accessibility Tools. Google says the logs are end-to-end encrypted, stored on its servers, and optional.
The logging system records device and network activity, then lets the owner decrypt and share it later, so a wipe or account closure does not immediately erase the trail. At the same time, blocking unverified apps from accessibility access cuts off a common route used by banking trojans and spyware to read screens, intercept input, and act without root.
For mobile investigators and teams supporting high-risk users, the shift is that useful evidence may now live in cloud-retained logs rather than on the phone itself. It also means some Android spyware will lose one of its easiest abuse paths, while the remaining forensic questions move toward who enabled logging and whether the preserved records were available before the incident ended.
2 sources covering this story
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Android 17 limits accessibility service access under Advanced Protection to verified Accessibility Tools, blocking a major malware abuse path.
Android 17 makes it harder for spyware to cover its tracks - Help Net Security
Google expands Android Advanced Protection with intrusion logging, USB safeguards, browser defenses and app security transparency.
Part of the PlainSec briefing for 2026-10-02