Google has expanded Android Advanced Protection with six security enhancements targeting spyware investigations, malicious USB connections, accessibility abuse, browser exploits, and repeated authentication failures.
Announced on October 1, 2026, the update strengthens Android 17 defenses for journalists, officials, public figures, and security-conscious users.
The changes build on Android 16’s device-level Advanced Protection, introduced in May 2025.
A single toggle coordinates security settings across Android, Chrome, Google Messages, and Phone by Google, preventing protections such as Google Play Protect and Scam Detection from being disabled while the mode remains active.
The centerpiece is Intrusion Logging, an optional forensic capability that records security and network activity, encrypts it end-to-end, and stores it on Google servers.
Recorded events include application process starts, installations, updates, removals, DNS lookups, IP connections, USB file transfers, certificate changes, and device locking or unlocking.
Users can download and decrypt records, then share them with trusted security specialists investigating whether, when, and how a compromise occurred.
Logs remain available for a rolling 12-month period and cannot be manually deleted before expiration, even after logging is disabled.
Activation requires separate consent within Advanced Protection settings; enabling the broader security mode alone does not activate logging.
The privacy tradeoff is significant: system-level logging captures network events generated by Chrome Incognito sessions.
Decrypted records require careful handling, and Google warns that legal obligations may compel disclosure of data or credentials in some jurisdictions.
USB Protection blocks new USB data connections while a supported device is locked, allowing charging without opening a data channel to an attached accessory or charging station.
Connections established while unlocked remain active after locking, including laptop transfers and wired Android Auto sessions.

Google describes that, the implementation, as a mobile industry first, designed to preserve evidence when attackers attempt to erase local traces.
Android 17 Advanced Protection
The feature is available on Pixel 6 and later devices and select Android 17 hardware. Manufacturer implementations can affect behavior, including fast charging.
Google’s documentation also notes that protection does not cover connections initiated while unlocked or the period before device boot completes.
Failed Authentication Lock automatically locks supported devices after repeated unsuccessful authentication attempts within settings or secured applications.
The safeguard addresses physical probing and brute-force attempts, although Google has not specified an attempt threshold in its announcement. Availability is limited to select Android 17 devices.
Android 17 Advanced Protection restricts AccessibilityService access to verified applications categorized as Accessibility Tools.
This targets services that malicious apps can abuse to read sensitive information, install malware, or obstruct removal, while retaining access for legitimate assistive technologies.

Chrome also disables WebGPU under Advanced Protection. Although the API supports advanced graphics and GPU-accelerated computation, removing it reduces exposure to complex browser attack surfaces rather than fixing a specifically identified vulnerability.
A new supporting-apps page identifies installed applications that check Advanced Protection status.
Developer APIs let apps query that status and receive runtime changes, enabling additional safeguards.developer.
Google says existing users will receive notifications when the enhancements reach their devices.
All six capabilities apply to Android 17, subject to the USB Protection and Failed Authentication Lock hardware exceptions; Intrusion Logging still requires manual activation.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

