Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and unauthorized access.
Announced on October 1, 2026, the changes combine stronger restrictions with tools that preserve evidence when someone suspects their phone has been compromised.
The update expands protections introduced with Android 16 rather than announcing a newly discovered malware campaign.
Building on Android 16 security protections, the approach brings security controls together for journalists, elected officials, public figures and other users facing elevated risks.
Google Security noted that malicious applications abuse accessibility permissions to read sensitive information, install malware or prevent removal.
Google said in a report shared publicly and reviewed by Cyber Security News (CSN) that the enhancements address these threats alongside browser exploits and physical tampering.
Advanced Protection uses one switch to strengthen settings across Chrome, Google Messages and Phone by Google.
It also prevents foundational protections, including Google Play Protect and Scam Detection, from being disabled. The announcement provides no victim totals or evidence of a specific attack campaign.
The six features cover different stages of a potential compromise, from restricting risky access to preserving investigation records.
Google says four are available on Android 17 devices generally, while USB Protection and Failed Authentication Lock are limited to selected devices.
The permission restrictions address behavior seen in fake streaming app attacks, where users were persuaded to grant accessibility access before attackers watched screens and controlled devices. Google does not claim the new controls eliminate every possible infection route.
Disabling WebGPU also narrows exposure to a component implicated in actively exploited Chrome vulnerabilities, although the Android announcement does not identify a particular vulnerability as its trigger. The change reduces available functionality rather than describing a standalone patch.
Intrusion Logging helps address the difficulty of investigating mobile compromise after attackers erase local traces. Amnesty International and Reporters Without Borders described encrypted, remotely stored records as useful evidence for suspected spyware attacks, particularly against journalists and other vulnerable individuals.
Google recommends that existing Advanced Protection users watch for a notification when the capabilities reach their devices.
Anyone seeking the forensic benefits must open Advanced Protection settings and manually enable Intrusion Logging; activating the broader mode does not automatically start recording.
Hardware differences also matter. Google cautions that USB Protection may affect functionality, including charging speeds, while a device is locked.
Users should distinguish protections enabled through the main switch from optional logging and device-dependent features when reviewing what their phone actually supports. These differences determine which safeguards are available.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…
The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…
Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…
The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…
Credentials that always work are credentials worth stealing which is why mitigating how attackers exploit…
Trump Mobile customers’ personal data has appeared on a dark web leak site after a…