Malicious Android apps force adware on users by hijacking the Android Accessibility Service and can be extremely difficult to uninstall
Dan Goodin / Ars Technica :
Context & Ripple Effects
This report extends a string of Android adware discoveries Ars Technica has tracked since early November, when researchers documented 20K root-exploiting adware samples on third-party app stores that were nearly impossible to remove. The new wrinkle is the delivery mechanism: rather than exploiting OS bugs, these apps abuse the Android Accessibility Service — a legitimate feature built for users with disabilities — to install ads and block their own removal.
The technique matters because it turns Google's own accessibility framework into the attack surface, and it foreshadows the scale later seen in Play Store campaigns like SimBad in 200+ games and the CooTek adware embedded in apps with 440M+ installs.
First-order effects
- Users who granted accessibility permissions to infected apps face forced adware and devices where standard uninstall paths fail, leaving manual cleanup as the only recourse.
Second-order effects
- Google faces pressure to tighten how apps request and keep Accessibility Service permissions in Play Store review, since the same mechanism keeps reappearing across campaigns.
Third-order effects
- If permission-abuse of trusted OS features keeps outpacing store vetting, Android's security model shifts from patching vulnerabilities to policing legitimate APIs — with app-store gatekeeping becoming the primary control point.
The trend: Mobile adware is migrating from third-party stores into mainstream distribution by weaponizing legitimate Android permissions rather than OS flaws.