Listen to this Post
2025-02-15
:
In an effort to enhance security for Android users, Google is rolling out a new in-call feature designed to block certain actions during phone calls that are often exploited by scammers. This update aims to protect users from a growing scam tactic that uses phone calls to trick individuals into enabling malicious settings on their devices. By making these changes, Google hopes to reduce the risk of malware infections and unwanted data access.
Summary:
Google is introducing a new feature in Android 16 Beta 2 that blocks users from enabling certain sensitive settings while on a phone call. The primary target of this security measure is to prevent users from installing apps from unknown sources or granting accessibility permissions during a call. The feature is a direct response to an increasingly common scam known as telephone-oriented attack delivery (TOAD), which involves cybercriminals sending SMS messages to persuade users to call a number and take actions that expose them to malware.
The security update displays a message to users who attempt to modify these settings during a call, warning them that scammers often use this method. The system blocks changes to settings like installing apps from unknown sources or granting accessibility access to apps during an active phone call. The feature aims to prevent the installation of malware, particularly dropper apps, which have been used in these types of attacks.
The new feature is already live in Android 16 Beta 2, and Google has expanded its security measures in recent months to further prevent fraud. In addition to blocking unauthorized app installations, Google has also started restricting sideloading of potentially harmful apps in certain regions, including Brazil, India, and the Philippines.
What Undercode Says:
This latest Android security update represents an important step in combating a growing form of mobile cybercrime that is gaining traction. The TOAD method, which involves tricking users into performing actions that they wouldn’t normally do, often by exploiting their trust or manipulating their sense of urgency, is a growing concern. Cybercriminals use phone calls to direct users to install apps that appear harmless but contain hidden malware.
One of the key aspects of this update is the focus on blocking users from enabling settings related to installing apps from unknown sources. This is a critical move, as it limits the ability for scammers to bypass Google’s Play Store restrictions and install potentially harmful apps from unofficial sources. Sideloading apps, especially those coming from unknown or dubious sources, is a common tactic used in phishing and scam campaigns. Scammers often use social engineering tactics to convince users that they need to install an app immediately, sometimes offering fake prizes, exclusive offers, or urgent system updates.
Another significant component of this update is the restriction on granting accessibility permissions to apps during phone calls. Accessibility access is a powerful feature that allows apps to control the device in ways that could be exploited by malicious actors to carry out attacks like stealing information, tracking user activities, or even controlling the device remotely. By blocking this action during a phone call, Google is effectively mitigating the risk of scam apps taking advantage of a user’s trust in a live conversation.
It’s also worth noting that Google has taken a broader approach to mobile security, expanding its restricted settings over time. The implementation of this new feature is a natural extension of previous measures that Google has introduced, such as automatically blocking the sideloading of risky apps in certain countries. Countries like Brazil, India, and the Philippines, where mobile scams are particularly prevalent, will benefit from these enhanced protections, making it more difficult for fraudsters to deliver malware.
This update not only addresses specific scam techniques but also serves as a reminder of how important it is to maintain vigilant, proactive security measures in an increasingly complex digital landscape. The fact that this feature is live in Android 16 Beta 2 suggests that Google is already working to integrate it seamlessly into their upcoming Android releases. As more Android users adopt newer versions of the operating system, this feature will become a key line of defense against mobile scams.
From an analytical standpoint, it’s clear that Google’s approach is becoming more comprehensive. While the new feature directly targets the methods used by cybercriminals to compromise devices, it also highlights the growing complexity of mobile security. With scams becoming more sophisticated, security measures must evolve to match the increasing risk.
Google’s strategy here—block certain risky actions during specific contexts, like phone calls—also highlights a shift toward context-aware security. It’s no longer enough to simply block apps from installing or stop users from granting permissions; the system must now recognize the context in which those actions are being requested. This intelligent, situation-based security measure can help reduce friction for legitimate users while still protecting them from malicious threats.
In conclusion, Google’s new in-call security feature for Android is a significant step toward safeguarding users against phone call-based scams. By focusing on blocking actions that are commonly exploited by scammers, the company is taking a proactive approach to combat an ever-evolving threat landscape. This initiative, combined with broader regional security enhancements, shows that Google is committed to improving mobile security and ensuring that Android remains a safe platform for its millions of users.
References:
Reported By: https://thehackernews.com/2025/02/androids-new-feature-blocks-fraudsters.html
https://www.quora.com/topic/Technology
Wikipedia: https://www.wikipedia.org
Undercode AI: https://ai.undercodetesting.com
Image Source:
OpenAI: https://craiyon.com
Undercode AI DI v2: https://ai.undercode.help




