Tendvane

← All articles

SecurityOctober 2, 2026

Android just made the request every banking trojan relies on useless

Nearly every Android banking trojan of the past five years has the same moment in it: a screen asking you to switch on an accessibility service. Google has now made that request pointless on phones that want it to be.

Advanced Protection in Android 17 gained six abilities on 1 October, and the important one restricts the AccessibilityService API to apps Google has verified as genuine accessibility tools. Screen readers, Braille displays, switch input and voice control carry on working. Anything else asking for the same powers gets a Restricted by Advanced Protection refusal. That API is enormously powerful by design, because it has to read what is on screen and tap things on your behalf, which is precisely why malware wants it. We covered one trojan that used it to ask a chatbot where to tap next.

The other five are worth knowing about too. USB connections drop to charging only while the phone is locked. The device locks hard after repeated failed unlock attempts. WebGPU is switched off in Chrome. Intrusion Logging keeps an encrypted twelve month record you can hand to an investigator if something goes wrong. And a new page lists which of your installed apps can see that Advanced Protection is on. USB Protection and the failed authentication lock need a Pixel 6 or newer, or one of a handful of other Android 17 phones; the rest work on any Android 17 device.

Turning it on is a single toggle in Settings, and the main thing most people will notice afterwards is that installing apps from outside the Play Store stops working. That trade is a good one. The same question applies to the computer in the house: has anything been granted more reach than it needs? Tendvane's safety check for unwanted software is the pass that brings those things to the surface.

Sources

Download Tendvane