การเปลี่ยนแปลงลักษณะการทำงาน: แอปที่กำหนดเป้าหมายเป็น Android 17 ขึ้นไป

เช่นเดียวกับรุ่นก่อนหน้า Android 17 มีการเปลี่ยนแปลงลักษณะการทำงานที่อาจส่งผลต่อแอปของคุณ การเปลี่ยนแปลงลักษณะการทำงานต่อไปนี้จะมีผลเฉพาะกับแอปที่กำหนดเป้าหมายเป็น Android 17 ขึ้นไป หากแอปกำหนดเป้าหมายเป็น Android 17 ขึ้นไป คุณควรแก้ไขแอปให้รองรับลักษณะการทำงานเหล่านี้ในกรณีที่เกี่ยวข้อง

นอกจากนี้ โปรดดูรายการการเปลี่ยนแปลงลักษณะการทำงานที่มีผลต่อแอปทั้งหมด ที่ทำงานบน Android 17 ไม่ว่าtargetSdkVersionของแอปจะเป็นอย่างไร

ประสบการณ์ของผู้ใช้และ UI ของระบบ

Android 17 มีการเปลี่ยนแปลงต่อไปนี้ซึ่งมีจุดประสงค์เพื่อสร้างประสบการณ์ของผู้ใช้ที่สอดคล้องกันและใช้งานง่ายยิ่งขึ้น

วิดเจ็ตขีดจำกัดหน่วยความจำ

Beginning with Android 17, for apps targeting Android 17 (API level 37) or higher, the system enforces a strict memory limit (1.5 * screen width * screen height * 4) against the combined memory usage of both Bitmaps and Icons present in the RemoteViews parcel. Exceeding these limits throws a fatal IllegalArgumentException and crashes the app's process.

For more information, see UpdateAppWidget.

ฟังก์ชันหลัก

Android 17 มีการเปลี่ยนแปลงต่อไปนี้ซึ่งแก้ไขหรือ ขยายความสามารถหลักต่างๆ ของระบบ Android

การใช้งาน MessageQueue แบบใหม่ที่ไม่มีการล็อก

Beginning with Android 17, apps targeting Android 17 (API level 37) or higher receive a new lock-free implementation of android.os.MessageQueue. The new implementation improves performance and reduces missed frames, but may break clients that reflect on MessageQueue private fields and methods.

For more information, including mitigation strategies, see MessageQueue behavior change guidance.

ตอนนี้ฟิลด์สุดท้ายแบบคงที่แก้ไขไม่ได้แล้ว

Apps running on Android 17 or higher that target Android 17 (API level 37) or higher cannot change static final fields. If an app attempts to change a static final field by using reflection, it will cause an IllegalAccessException. Attempting to modify one of these fields through JNI APIs (such as SetStaticLongField()) will cause the app to crash.

การช่วยเหลือพิเศษ

Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงการช่วยเหลือพิเศษ

การรองรับการช่วยเหลือพิเศษสำหรับการพิมพ์ด้วยแป้นพิมพ์จริงของ IME ที่ซับซ้อน

This feature introduces new AccessibilityEvent and TextAttribute APIs to enhance screen reader spoken feedback for CJKV language input. CJKV IME apps can now signal whether a text conversion candidate has been selected during text composition. Apps with edit fields can specify text change types when sending text changed accessibility events. For example, apps can specify that a text change occurred during text composition, or that a text change resulted from a commit. Doing this enables accessibility services such as screen readers to deliver more precise feedback based on the nature of the text modification.

App adoption

  • IME Apps: When setting composing text in edit fields, IMEs can use TextAttribute.Builder.setTextSuggestionSelected() to indicate whether a specific conversion candidate was selected.

  • Apps with Edit Fields: Apps that maintain a custom InputConnection can retrieve candidate selection data by calling TextAttribute.isTextSuggestionSelected(). These apps should then call AccessibilityEvent.setTextChangeTypes() when dispatching TYPE_VIEW_TEXT_CHANGED events. Apps targeting Android 17 (API level 37) that use the standard TextView will have this feature enabled by default. (That is, TextView will handle retrieving data from the IME and setting text change types when sending events to accessibility services).

  • Accessibility Services: Accessibility services that process TYPE_VIEW_TEXT_CHANGED events can call AccessibilityEvent.getTextChangeTypes() to identify the nature of the modification and adjust their feedback strategies accordingly.

ความเป็นส่วนตัว

Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงความเป็นส่วนตัวของผู้ใช้

เปิดใช้ ECH (ClientHello ที่เข้ารหัส) แล้ว

Android 17 introduces platform support for Encrypted Client Hello (ECH), a TLS extension that enhances user privacy by encrypting the Server Name Indication (SNI) in the TLS handshake. This encryption helps prevent network observers from easily identifying the specific domain your app is connecting to.

For apps targeting Android 17 (API level 37) or higher, ECH is used for TLS connections. ECH is active only if the networking library used by the app (for example, HttpEngine, WebView, or OkHttp) has integrated ECH support and the remote server also supports the ECH protocol. If ECH cannot be negotiated, the client sends an ECH extension with randomized contents (a mechanism called ECH GREASE). See RFC 9849 for more details on how ECH GREASE works.

To allow apps to customize this behavior, Android 17 adds a new <domainEncryption> element to the Network Security Configuration file. Developers can use <domainEncryption> within <base-config> or <domain-config> tags to select an ECH mode (for example, "enabled" or "disabled") on a global or per-domain basis.

For more information, see the Encrypted Client Hello documentation.

ต้องมีสิทธิ์เข้าถึงเครือข่ายภายในสำหรับแอปที่กำหนดเป้าหมายเป็น Android 17

Android 17 introduces the ACCESS_LOCAL_NETWORK runtime permission to protect users from unauthorized local network access. Because this falls under the existing NEARBY_DEVICES permission group, users who have already granted other NEARBY_DEVICES permissions aren't prompted again. This new requirement prevents malicious apps from exploiting unrestricted local network access for covert user tracking and fingerprinting. By declaring and requesting this permission, your app can discover and connect to devices on the local area network (LAN), such as smart home devices or casting receivers.

Apps targeting Android 17 (API level 37) or higher now have two paths to maintain communication with LAN devices: Adopt system-mediated, privacy-preserving device pickers to skip the permission prompt, or explicitly request this new permission at runtime to maintain local network communication.

For more information, see the Local network permission documentation.

ซ่อนรหัสผ่านจากอุปกรณ์จริง

หากแอปกำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) ขึ้นไปและผู้ใช้กำลังใช้อุปกรณ์ป้อนข้อมูลจริง (เช่น แป้นพิมพ์ภายนอก) ระบบปฏิบัติการ Android จะใช้การตั้งค่า show_passwords_physical ใหม่กับอักขระทั้งหมดในช่องรหัสผ่าน โดยค่าเริ่มต้น การตั้งค่านั้นจะซ่อนอักขระรหัสผ่านทั้งหมด

ระบบ Android จะแสดงอักขระรหัสผ่านที่พิมพ์ล่าสุดเพื่อช่วยให้ผู้ใช้ทราบ ว่าพิมพ์รหัสผ่านผิดหรือไม่ อย่างไรก็ตาม แป้นพิมพ์ลัดเหล่านี้จะมีความจำเป็นน้อยกว่ามากเมื่อใช้กับแป้นพิมพ์ภายนอกขนาดใหญ่ นอกจากนี้ อุปกรณ์ที่มีแป้นพิมพ์ภายนอกมักมี จอแสดงผลขนาดใหญ่กว่า ซึ่งเพิ่มความเสี่ยงที่ผู้อื่นจะเห็นรหัสผ่านที่พิมพ์

หากผู้ใช้ใช้หน้าจอสัมผัสของอุปกรณ์ ระบบจะใช้การตั้งค่า show_passwords_touchใหม่

การปกป้อง OTP สำหรับข้อความ SMS มาตรฐาน

ตั้งแต่ Android 17 เป็นต้นไป Android จะขยายการป้องกัน OTP ทาง SMS ให้ครอบคลุมข้อความ SMS มาตรฐาน (ข้อความ SMS ที่มี OTP ซึ่งไม่ได้ ใช้รูปแบบ WebOTP หรือ SMS Retriever) สำหรับแอปส่วนใหญ่ที่กำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) ขึ้นไป ข้อความ SMS เหล่านี้จะ พร้อมใช้งานหลังจากได้รับ 3 ชั่วโมง ความล่าช้านี้มีจุดประสงค์เพื่อช่วย ป้องกันการลักลอบใช้ OTP ในระหว่างการหน่วงเวลา 3 ชั่วโมงนี้ ระบบจะระงับการออกอากาศของSMS_RECEIVED_ACTION และกรองการค้นหาฐานข้อมูลของผู้ให้บริการ SMS ข้อความ SMS จะพร้อมใช้งานในแอปเหล่านี้หลังจากที่เกิดความล่าช้า

แอปบางแอป เช่น แอปผู้ช่วย SMS เริ่มต้น แอปคู่หูของอุปกรณ์ที่เชื่อมต่อ ฯลฯ จะได้รับการยกเว้นจากความล่าช้านี้ แอปทั้งหมดที่ต้องอ่านข้อความ SMS เพื่อดึงข้อมูล OTP ควรเปลี่ยนไปใช้ SMS Retriever หรือ SMS User Consent API เพื่อให้ฟังก์ชันการทำงานยังคงดำเนินต่อไปได้

ความปลอดภัย

Android 17 มีการปรับปรุงความปลอดภัยของอุปกรณ์และแอปดังนี้

ความปลอดภัยของกิจกรรม

ใน Android 17 แพลตฟอร์มจะยังคงเปลี่ยนไปใช้สถาปัตยกรรม "ปลอดภัยโดยค่าเริ่มต้น" พร้อมเปิดตัวชุดการปรับปรุงที่ออกแบบมาเพื่อลดช่องโหว่ที่มีความรุนแรงสูง เช่น ฟิชชิง การลักลอบใช้การโต้ตอบ และการโจมตีแบบ Confused Deputy การอัปเดตนี้กำหนดให้นักพัฒนาแอปเลือกใช้ มาตรฐานความปลอดภัยใหม่โดยชัดแจ้งเพื่อรักษาความเข้ากันได้ของแอปและการปกป้องผู้ใช้

ผลกระทบที่สำคัญสำหรับนักพัฒนาแอปมีดังนี้

  • การปิดช่องโหว่ BAL และการเลือกใช้ที่ปรับปรุงแล้ว: เรากำลังปรับปรุงข้อจำกัดการเปิดใช้กิจกรรมในเบื้องหลัง (BAL) โดยขยายการปกป้องไปยัง IntentSender นักพัฒนาแอปต้องย้ายข้อมูลออกจากค่าคงที่ MODE_BACKGROUND_ACTIVITY_START_ALLOWED รุ่นเดิม แต่คุณควร ใช้การควบคุมแบบละเอียด เช่น MODE_BACKGROUND_ACTIVITY_START_ALLOW_IF_VISIBLE ซึ่งจำกัด การเริ่มต้นกิจกรรมไว้ในสถานการณ์ที่แอปโทรปรากฏให้เห็น ซึ่งจะช่วย ลดพื้นผิวการโจมตีได้อย่างมาก
  • เครื่องมือในการนำไปใช้: นักพัฒนาแอปควรใช้โหมดเข้มงวดและการตรวจสอบ Lint ที่อัปเดตแล้ว เพื่อระบุรูปแบบเดิมและเตรียมพร้อมสำหรับข้อกำหนดของ SDK เป้าหมายในอนาคต

เปิดใช้ CT โดยค่าเริ่มต้น

หากแอปกำหนดเป้าหมายเป็น Android 17 (API ระดับ 37) ขึ้นไป ระบบจะเปิดใช้ ความโปร่งใสของใบรับรอง (CT) โดยค่าเริ่มต้น (ใน Android 16 CT จะพร้อมใช้งาน แต่แอปต้องเลือกใช้)

DCL แบบเนทีฟที่ปลอดภัยยิ่งขึ้น - C

If your app targets Android 17 (API level 37) or higher, the Safer Dynamic Code Loading (DCL) protection introduced in Android 14 for DEX and JAR files now extends to native libraries.

All native files loaded using System.load() must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError.

We recommend that apps avoid dynamically loading code whenever possible, as doing so greatly increases the risk that an app can be compromised by code injection or code tampering.

จำกัดฟิลด์ PII ในมุมมองข้อมูล CP2

สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) ขึ้นไป Contacts Provider 2 (CP2) จะจำกัดคอลัมน์บางรายการที่มีข้อมูลส่วนบุคคลที่ระบุตัวบุคคลนั้นได้ (PII) จากมุมมองข้อมูล เมื่อเปิดใช้การเปลี่ยนแปลงนี้ ระบบจะนำคอลัมน์เหล่านี้ออกจากมุมมองข้อมูลเพื่อเพิ่มความเป็นส่วนตัวของผู้ใช้ คอลัมน์ที่ถูกจำกัด ได้แก่

แอปที่ใช้คอลัมน์เหล่านี้จาก ContactsContract.Data สามารถดึงข้อมูลจาก ContactsContract.RawContacts แทนได้โดยการรวมกับ RAW_CONTACT_ID

บังคับใช้การตรวจสอบ SQL อย่างเข้มงวดใน CP2

สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (API ระดับ 37) ขึ้นไป Contacts Provider 2 (CP2) จะบังคับใช้การตรวจสอบคำสั่ง SQL อย่างเข้มงวดเมื่อมีการเข้าถึงตาราง ContactsContract.Data โดยไม่มีสิทธิ์ READ_CONTACTS

การเปลี่ยนแปลงนี้จะทำให้ระบบตั้งค่าตัวเลือกStrictColumnsและ StrictGrammarเมื่อค้นหาตาราง ContactsContract.Data หากแอปไม่มีสิทธิ์READ_CONTACTS หากคำค้นหา ใช้รูปแบบที่ไม่เข้ากันกับรูปแบบเหล่านี้ ระบบจะ ปฏิเสธและทำให้เกิดข้อยกเว้น

การตรวจหา

Android 17 มีการเปลี่ยนแปลงต่อไปนี้ในด้านระบบอัจฉริยะ

การเลิกใช้งาน setContentCaptureEnabled

Content Capture is enabled by default on certain devices to allow on-device AI features to analyze screen contents for intelligent experiences.

Starting in Android 17, the ContentCaptureManager.setContentCaptureEnabled(boolean) API method is deprecated. For apps that target Android 17 (API level 37) or higher, calling setContentCaptureEnabled(false) no longer disables Content Capture.

If your app needs to continue disabling Content Capture or restrict screen contents from being captured by the system, you must transition to using the FLAG_SECURE window layout parameter.

To disable Content Capture, set the FLAG_SECURE flag on your window as shown in the following example:

Kotlin

window.setFlags(
    WindowManager.LayoutParams.FLAG_SECURE,
    WindowManager.LayoutParams.FLAG_SECURE
)

Java

getWindow().setFlags(
    WindowManager.LayoutParams.FLAG_SECURE,
    WindowManager.LayoutParams.FLAG_SECURE
);

For more details, see the WindowManager.LayoutParams.FLAG_SECURE reference documentation.

สื่อ

Android 17 มีการเปลี่ยนแปลงลักษณะการทำงานของสื่อต่อไปนี้

การปิดช่องโหว่ของเสียงที่เล่นขณะล็อกหน้าจอ

ตั้งแต่ Android 17 เป็นต้นไป เฟรมเวิร์กเสียงจะบังคับใช้ข้อจำกัดในการโต้ตอบเสียงในเบื้องหลัง ซึ่งรวมถึงการเล่นเสียง คำขอโฟกัสเสียง และ API การเปลี่ยนระดับเสียง เพื่อให้มั่นใจว่าผู้ใช้เป็นผู้เริ่มการเปลี่ยนแปลงเหล่านี้โดยเจตนา

แอปทั้งหมดมีข้อจำกัดด้านเสียงบางประการ อย่างไรก็ตาม ข้อจำกัดจะเข้มงวดมากขึ้นหากแอปกำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) หากแอปเหล่านี้ โต้ตอบกับเสียงขณะที่อยู่ในเบื้องหลัง แอปต้องมีบริการที่ทำงานอยู่เบื้องหน้า นอกจากนี้ แอปต้องเป็นไปตามข้อกำหนดข้อใดข้อหนึ่งหรือทั้ง 2 ข้อต่อไปนี้

  • บริการที่ทำงานอยู่เบื้องหน้าต้องมีความสามารถขณะใช้งาน (WIU)
  • แอปต้องมีสิทธิ์การปลุกที่แน่นอนและโต้ตอบกับสตรีมเสียง USAGE_ALARM

ดูข้อมูลเพิ่มเติม รวมถึงกลยุทธ์การลดความเสี่ยงได้ที่การเพิ่มความปลอดภัยของเสียงในเบื้องหลัง

รูปแบบของอุปกรณ์

Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงประสบการณ์ของผู้ใช้ ในอุปกรณ์ขนาดและรูปแบบต่างๆ

การเปลี่ยนแปลง API ของแพลตฟอร์มเพื่อไม่สนใจข้อจำกัดด้านการวางแนว ความสามารถในการปรับขนาด และสัดส่วนการแสดงผลบนหน้าจอขนาดใหญ่ (sw>=600dp)

เราได้เปิดตัวการเปลี่ยนแปลง Platform API ใน Android 16 เพื่อไม่สนใจข้อจำกัดด้านการวางแนว ความสามารถในการปรับขนาด และสัดส่วนการแสดงผลบนหน้าจอขนาดใหญ่ (sw >= 600dp) สำหรับแอปที่กำหนดเป้าหมายเป็น API ระดับ 36 ขึ้นไป นักพัฒนาแอปมีตัวเลือกในการเลือกไม่ใช้การเปลี่ยนแปลงเหล่านี้ ด้วย SDK 36 แต่ตัวเลือกการเลือกไม่ใช้นี้จะไม่มีให้บริการอีกต่อไป สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) ขึ้นไป

ดูข้อมูลเพิ่มเติมได้ที่ระบบจะไม่สนใจข้อจำกัดเกี่ยวกับ การวางแนวและการปรับขนาด

การเชื่อมต่อ

Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงความสอดคล้องและ สอดคล้องกับInputStream มาตรฐานของ Java สำหรับซ็อกเก็ต RFCOMM ของบลูทูธ

ลักษณะการทำงานของ read() ใน BluetoothSocket สำหรับ RFCOMM ที่สอดคล้องกัน

สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (API ระดับ 37) เมธอด read() ของ InputStream ที่ได้จาก BluetoothSocket ที่อิงตาม RFCOMM จะแสดงผลเป็น -1 เมื่อปิดซ็อกเก็ตหรือการเชื่อมต่อถูกตัด

การเปลี่ยนแปลงนี้จะทำให้ลักษณะการทำงานของซ็อกเก็ต RFCOMM สอดคล้องกับซ็อกเก็ต LE CoC และ สอดคล้องกับเอกสารประกอบมาตรฐาน InputStream.read() ซึ่งระบุว่าระบบจะแสดง -1 เมื่อถึงจุดสิ้นสุดของสตรีม

แอปที่อาศัยการดักจับ IOException เพียงอย่างเดียวเพื่อออกจากลูปการอ่านอาจได้รับผลกระทบจากการเปลี่ยนแปลงนี้ และควรอัปเดตลูปการอ่าน BluetoothSocket เพื่อตรวจสอบค่าที่ส่งคืนของ -1 อย่างชัดเจน ซึ่งจะช่วยให้มั่นใจได้ว่าลูปจะสิ้นสุดอย่างถูกต้องเมื่ออุปกรณ์ระยะไกลยกเลิกการเชื่อมต่อหรือปิดซ็อกเก็ต ดูตัวอย่างการติดตั้งใช้งานที่แนะนําได้ในข้อมูลโค้ดในคู่มือโอนข้อมูลผ่านบลูทูธ