Spyware often tries to erase traces of an attack, but Android 17 is giving investigators another place to look.
Google is expanding Advanced Protection with six new security capabilities aimed at targeted attacks, scams, physical access, and other threats. The centerpiece is Intrusion Logging, an opt-in feature that records security-relevant activity and stores encrypted copies in the cloud.
The logs are end-to-end encrypted and retained for a rolling 12 months. Users can later download and decrypt them and share the evidence with security experts investigating a suspected compromise. Google says it cannot read the encrypted logs.
The system can also record network activity from Chrome's Incognito tabs, although investigators can see visited domains rather than individual pages. The feature is optional and requires users to enable it separately inside Advanced Protection.
Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, called it a potential "game-changer for spyware accountability," saying evidence could remain available even after an attacker removes traces from the phone.
The most important idea here is not simply preventing a compromise. It is preserving evidence after one happens. That changes the equation for sophisticated spyware operators.
An attacker who manages to compromise a phone may still succeed in the initial intrusion, but removing every useful trace becomes more difficult when relevant records are stored away from the device.
For journalists, activists, executives, and others at elevated risk of targeted surveillance, that could make post-compromise forensic analysis more useful.
Android 17 also closes other attack paths
Intrusion Logging is only part of the update.
USB Protection blocks new USB data connections while a device is locked but still allows charging, reducing the risk of unauthorized data access through a physical connection. Connections established while the device was unlocked can remain active.
Android 17 also restricts Accessibility Service access to verified accessibility tools when Advanced Protection is enabled. That matters because malicious apps can abuse accessibility permissions to read sensitive information, manipulate the interface, and interfere with security controls.
Google is also disabling WebGPU in Chrome under Advanced Protection, reducing exposure to sophisticated browser-based attacks that could take advantage of hardware-accelerated web technologies.
Failed Authentication Lock adds another layer by locking the device after repeated failed authentication attempts in settings or secured apps.
What Android users need to know
Advanced Protection is aimed primarily at people who face elevated security risks, but some of its defenses can also help ordinary users, particularly against scam apps abusing accessibility privileges.
Not every feature is available on every phone. Google says USB Protection and Failed Authentication Lock are limited to select Android 17 devices, while USB Protection is available on Pixel 6 and newer models.
Users who already have Advanced Protection will receive a notification when the capabilities arrive. Crucially, Intrusion Logging does not activate automatically: users must manually opt in through the Advanced Protection settings.
Other news: Cisco is urging customers to patch an actively exploited Catalyst SD-WAN Manager flaw that can let unauthenticated remote attackers bypass authentication and gain administrator-level API access.





