{"id":2031,"date":"2025-02-17T10:06:54","date_gmt":"2025-02-17T10:06:54","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/17\/new-android-security-feature-that-blocks-changing-sensitive-setting-during-calls\/"},"modified":"2025-02-17T10:06:54","modified_gmt":"2025-02-17T10:06:54","slug":"new-android-security-feature-that-blocks-changing-sensitive-setting-during-calls","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/17\/new-android-security-feature-that-blocks-changing-sensitive-setting-during-calls\/","title":{"rendered":"New Android Security Feature that Blocks Changing Sensitive Setting During Calls"},"content":{"rendered":"<p>    New Android Security Feature that Blocks Changing Sensitive Setting During Calls<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has unveiled a groundbreaking security feature in <a href=\"https:\/\/cybersecuritynews.com\/rednote-ios-android-app-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Android<\/a> 16 Beta 2 aimed at combating phone scams by blocking users from altering sensitive settings during active phone calls.\u00a0<\/p>\n<p>This feature, currently live in the beta version, prevents enabling permissions like sideloading apps and granting accessibility access, both of which are commonly exploited by scammers.<\/p>\n<p>Phone scams have become increasingly sophisticated, often leveraging psychological manipulation to trick victims into granting permissions that enable malware installation.\u00a0<\/p>\n<p>A common tactic involves guiding victims over the phone to enable sideloading or accessibility permissions, which allow malicious apps to bypass safeguards and gain control of the device.<\/p>\n<p>Recognizing this <a href=\"https:\/\/cybersecuritynews.com\/firewall-authentication-bypass-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability<\/a>, Google has introduced \u201cin-call anti-scammer protection\u201d in Android 16.\u00a0<\/p>\n<p>Android Authority <a href=\"https:\/\/www.androidauthority.com\/android-16-phone-call-protections-3526068\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reports<\/a> that the system detects when a call is active, and blocks attempt to modify these critical settings. If a user tries to enable such permissions during a call, they are met with a warning message, such as:<\/p>\n<p>This proactive measure introduces friction into the scam process, potentially disrupting the scammer\u2019s flow and giving victims time to reconsider their actions.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Key Features of the New Security Measure<\/strong><\/h2>\n<h4 class=\"wp-block-heading\"><strong>Blocking Sideloading Permissions During Calls:<\/strong><\/h4>\n<p>Sideloading, which allows apps to install other apps outside official app stores, is disabled by default for security reasons.<\/p>\n<p>Android 16 now prevents users from enabling this permission while on a call. The feature builds on existing restrictions in Google\u2019s Advanced Protection Mode.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfAbzXKNkCSE_4HG7gur5f_zRU4W77K2OWl_8r30U_UhFl41ksGZlK5WT9_eeThE7_h4s8oAZzxRcxB6--na4_InZtCCO2rWUZDmbTkPAYZ758Jfr3ILSFoWwNBGF_82fQtNslqkw?key=PA3oBECwNhPxBPUfTDBqDO--\" alt=\"\"><figcaption class=\"wp-element-caption\">Google\u2019s Advanced Protection Mode<\/figcaption><\/figure>\n<\/div>\n<h4 class=\"wp-block-heading\"><strong>Restricting Accessibility Access:<\/strong><\/h4>\n<p>Accessibility permissions allow apps to read screen content and perform actions on behalf of users\u2014a capability often exploited by malware.<\/p>\n<p>Android 16 blocks granting these permissions during calls, further reducing the risk of unauthorized control.<\/p>\n<h4 class=\"wp-block-heading\"><strong>Warning Prompts:<\/strong><\/h4>\n<p>Users attempting to bypass these restrictions receive clear warnings about potential scams, encouraging them to verify the legitimacy of the caller.<\/p>\n<h4 class=\"wp-block-heading\"><strong>Enhanced Confirmation Mode:<\/strong><\/h4>\n<p>This feature extends protections introduced in Android 15, adding more stringent safeguards against unauthorized access to sensitive settings.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Technical Insights and Broader Implications<\/strong><\/h2>\n<p>The new <a href=\"https:\/\/cybersecuritynews.com\/windows-11-bypassed-arbitrary-code-kernel-mode\/\" target=\"_blank\" rel=\"noreferrer noopener\">security feature<\/a> is part of Google\u2019s ongoing efforts to enhance user safety amid rising threats like telephone-oriented attack delivery (TOAD) scams.\u00a0<\/p>\n<p>These scams often involve sending fraudulent SMS messages or inducing urgency through phone calls to trick users into installing malware.<\/p>\n<p>By integrating these protections into Android 16 Beta 2, Google aims to reduce fraud cases significantly. <\/p>\n<p>While scammers might still instruct victims to hang up and enable permissions later, the added step introduces enough friction to disrupt their tactics.<\/p>\n<p>Additionally, Android 16 includes broader security enhancements such as protection against intent redirection attacks and improved app compatibility for large-screen devices.\u00a0<\/p>\n<p>The anti-scammer protections are currently live in Android 16 Beta 2, available for Pixel devices (Pixel 6 and newer).\u00a0<\/p>\n<p>The final <a href=\"https:\/\/android-developers.googleblog.com\/2025\/02\/second-beta-android16.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">release<\/a> of Android 16 is expected later in Q2 2025. With these features set for public rollout, users can look forward to a safer mobile experience that prioritizes privacy and fraud prevention.<\/p>\n<p>As scams grow more sophisticated with advancements in AI, Google\u2019s new approach marks a significant step toward mitigating risks and empowering users with robust defenses against <a href=\"https:\/\/cybersecuritynews.com\/how-to-track-evolving-cyber-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">cyber threats<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>PCI DSS 4.0 &amp; Supply Chain Attack Prevention \u2013\u00a0<a href=\"https:\/\/webinars.indusface.com\/reducing-3rd-party-risks-pci-dss-and-supply-chain-attack-prevention\/register?utm_source=gbhackers-side-banner&amp;utm_campaign=2025-feb-webinar-pci-dss&amp;utm_medium=referral\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-android-security-feature-that-blocks\/\">New Android Security Feature that Blocks Changing Sensitive Setting During Calls<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-android-security-feature-that-blocks\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Android Security Feature that Blocks Changing Sensitive Setting During Calls Google has unveiled a groundbreaking security feature in Android 16 Beta 2 aimed at combating phone scams by blocking users from altering sensitive settings during active phone calls.\u00a0 This feature, currently live in the beta version, prevents enabling permissions like sideloading apps and granting [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[509,129,63],"tags":[130],"class_list":["post-2031","post","type-post","status-publish","format-standard","hentry","category-android","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2031"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2031"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2031\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2031"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2031"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2031"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}