Android 17 Advanced Protection adds spyware forensic logs
Google has added six features to Advanced Protection in Android 17. One of them targets a familiar problem in spyware investigations: the evidence often disappears from the phone once the attacker cleans up.
The question matters most to people such as journalists, who may suspect their device has been compromised and then find nothing left to examine. The new release addresses this by keeping a copy of security records away from the handset itself. People already using Advanced Protection will get a notification when the new capabilities reach their devices.
Logs that survive a cleanup
The headline feature is Intrusion Logging. It records security and network events on the device, including app activity. If a user suspects a compromise, they can download the logs, decrypt them and hand them to trusted security experts for analysis.
The logs are end-to-end encrypted and synced to Google's servers. Google says it has no way to read them.
Network activity from Chrome's Incognito tabs is also captured. Anyone with access to the decrypted logs can see which websites were visited, but not the individual pages on those sites.
Retention works on a rolling 12-month basis, after which the logs are deleted automatically. Neither the user nor Google can remove them early. This applies even if logging is switched off or the account is closed. Once a user downloads and decrypts a copy, keeping it safe is their responsibility.
Intrusion Logging is not on by default. Users have to opt in separately from the Advanced Protection settings page.
Google built the feature together with civil liberties and press freedom organizations. Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, called it the first purpose-built forensic logging for targeted attacks on a consumer mobile platform. He noted that the tamper-resistant logs can be retrieved and analyzed "even if the attacker has erased their tracks on the device itself," and described it as "a potential game-changer for spyware accountability."
Locking down the charging port
USB Protection blocks new USB data connections while the phone is locked. The aim is to stop unauthorized access through the charging port. It is available on Pixel 6 and later models and on selected Android 17 devices. It switches on automatically when users enable Device protection in the Advanced Protection settings.
Charging over USB still works. Fast charging, however, may sometimes require the phone to be unlocked.
Connections made while the phone is unlocked, such as photo transfers or wired Android Auto, stay active after the screen locks. The protection kicks in once the phone has finished booting. A short grace period lets a dropped USB connection resume on a locked screen, which helps with loose ports and flaky cables.
Reining in accessibility abuse
Google says apps that misuse the AccessibilityService API are still a primary route for fraud and scams. Accessibility services interact directly with the screen. That gives a malicious app the ability to read sensitive data, install malware or block its own removal, a pattern seen in threats such as the RemControl banking trojan.
With Advanced Protection enabled on Android 17, only verified apps classified as accessibility tools can use these services. Such tools mainly support people with disabilities. Google says the goal is to stop misuse without cutting off assistive technology.
Browser and theft protections
Advanced Protection now also turns off WebGPU in Chrome. WebGPU lets websites tap a device's graphics processor for demanding graphics and computing work, including AI processing. Google says disabling it shrinks exposure to sophisticated browser exploits.
Failed Authentication Lock, an existing anti-theft feature, joins Advanced Protection on selected Android 17 devices. It locks the phone automatically after repeated failed authentication attempts in settings or in secured apps. This helps against physical tampering and brute-force attempts.
Which apps are paying attention
A new settings page called View Supporting Apps lists installed apps that check whether Advanced Protection is turned on, according to Il-Sung Lee, Group Product Manager for Android Security.
Developers can be notified when a user enables the mode. Their apps can then switch on extra security and privacy features automatically.
Our Take
Most of the Android 17 additions harden the device. Intrusion Logging is different because it focuses on what happens after an attack. This suggests Google is treating post-incident investigation as part of mobile defense, not just prevention. That shift is relevant given recent reports such as Ukraine's warning about Russian mobile malware on iOS and Android and the continued commercial growth of vendors like the Paragon spyware maker.
The design involves trade-offs. Logs that cannot be deleted early, and that include Incognito browsing at the site level, help investigators. They also create a sensitive record that users must handle carefully once it is decrypted. At-risk users should weigh this before opting in.
It is worth watching whether forensic groups such as Amnesty's Security Lab start citing these logs in published investigations. Another open question is whether other mobile platforms follow with similar off-device logging. The accessibility restrictions could also affect banking malware that depends on that API, although real-world impact will depend on how many people actually enable Advanced Protection.
