Particle.news

Google Expands Advanced Protection in Android 17 With Encrypted Forensics and Hardware Shields

Encrypted cloud forensic logs plus USB data‑blocking defaults and tighter app and browser controls give high‑risk users tools to detect compromises and resist targeted spyware.

Overview

  • Google added six Advanced Protection features for Android 17 that include Intrusion Logging, USB Protection, AccessibilityService restrictions, WebGPU disablement in Chrome, Failed Authentication Lock, and a View Supporting Apps transparency page.
  • Intrusion Logging is optional and stores end‑to‑end encrypted security and network events in the cloud for a rolling 12 months so users can download and decrypt logs for expert analysis while Google says it cannot read the encrypted data.
  • USB Protection defaults new physical USB connections to charging‑only when the device is locked to block unauthorized data access, with the feature available on Pixel 6+ and select Android 17 devices and existing unlocked connections left active after lock.
  • Android 17 Advanced Protection limits AccessibilityService access to verified apps classified as Accessibility Tools and disables WebGPU in Chrome to reduce known attack paths used by spyware and browser exploits.
  • The program is aimed at journalists, elected officials and other high‑risk users, Google worked with civil‑liberties groups on forensic logging, existing Advanced Protection users will be notified of the rollout, and some protections require Android 17 or specific hardware so coverage will vary.