เช่นเดียวกับรุ่นก่อนหน้า Android 17 มีการเปลี่ยนแปลงลักษณะการทำงานที่อาจส่งผลต่อแอปของคุณ การเปลี่ยนแปลงลักษณะการทำงานต่อไปนี้จะมีผลเฉพาะกับแอปที่กำหนดเป้าหมายเป็น Android 17 ขึ้นไป หากแอปกำหนดเป้าหมายเป็น Android 17 ขึ้นไป คุณควรแก้ไขแอปให้รองรับลักษณะการทำงานเหล่านี้ในกรณีที่เกี่ยวข้อง
นอกจากนี้ โปรดดูรายการการเปลี่ยนแปลงลักษณะการทำงานที่มีผลต่อแอปทั้งหมด
ที่ทำงานบน Android 17 ไม่ว่าtargetSdkVersionของแอปจะเป็นอย่างไร
ประสบการณ์ของผู้ใช้และ UI ของระบบ
Android 17 มีการเปลี่ยนแปลงต่อไปนี้ซึ่งมีจุดประสงค์เพื่อสร้างประสบการณ์ของผู้ใช้ที่สอดคล้องกันและใช้งานง่ายยิ่งขึ้น
วิดเจ็ตขีดจำกัดหน่วยความจำ
Beginning with Android 17, for apps targeting
Android 17 (API level 37) or higher, the system enforces a strict memory
limit (1.5 * screen width * screen height * 4) against the combined memory usage
of both Bitmaps and Icons present in the RemoteViews parcel. Exceeding these
limits throws a fatal IllegalArgumentException and crashes the app's process.
For more information, see UpdateAppWidget.
ฟังก์ชันหลัก
Android 17 มีการเปลี่ยนแปลงต่อไปนี้ซึ่งแก้ไขหรือ ขยายความสามารถหลักต่างๆ ของระบบ Android
การใช้งาน MessageQueue แบบใหม่ที่ไม่มีการล็อก
Beginning with Android 17, apps targeting Android 17 (API level 37)
or higher receive a new lock-free implementation of
android.os.MessageQueue. The new implementation improves performance and
reduces missed frames, but may break clients that reflect on MessageQueue
private fields and methods.
For more information, including mitigation strategies, see MessageQueue behavior change guidance.
ตอนนี้ฟิลด์สุดท้ายแบบคงที่แก้ไขไม่ได้แล้ว
Apps running on Android 17 or higher that target
Android 17 (API level 37) or higher cannot change static final fields. If
an app attempts to change a static final field by using reflection, it will
cause an IllegalAccessException. Attempting to modify one of these fields
through JNI APIs (such as SetStaticLongField()) will cause the app to crash.
การช่วยเหลือพิเศษ
Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงการช่วยเหลือพิเศษ
การรองรับการช่วยเหลือพิเศษสำหรับการพิมพ์ด้วยแป้นพิมพ์จริงของ IME ที่ซับซ้อน
This feature introduces new AccessibilityEvent and TextAttribute
APIs to enhance screen reader spoken feedback for CJKV language input. CJKV IME
apps can now signal whether a text conversion candidate has been selected during
text composition. Apps with edit fields can specify text change types when
sending text changed accessibility events.
For example, apps can specify that a text change occurred during text
composition, or that a text change resulted from a commit.
Doing this enables accessibility
services such as screen readers to deliver more precise feedback based on the
nature of the text modification.
App adoption
IME Apps: When setting composing text in edit fields, IMEs can use
TextAttribute.Builder.setTextSuggestionSelected()to indicate whether a specific conversion candidate was selected.Apps with Edit Fields: Apps that maintain a custom
InputConnectioncan retrieve candidate selection data by callingTextAttribute.isTextSuggestionSelected(). These apps should then callAccessibilityEvent.setTextChangeTypes()when dispatchingTYPE_VIEW_TEXT_CHANGEDevents. Apps targeting Android 17 (API level 37) that use the standardTextViewwill have this feature enabled by default. (That is,TextViewwill handle retrieving data from the IME and setting text change types when sending events to accessibility services).Accessibility Services: Accessibility services that process
TYPE_VIEW_TEXT_CHANGEDevents can callAccessibilityEvent.getTextChangeTypes()to identify the nature of the modification and adjust their feedback strategies accordingly.
ความเป็นส่วนตัว
Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงความเป็นส่วนตัวของผู้ใช้
เปิดใช้ ECH (ClientHello ที่เข้ารหัส) แล้ว
Android 17 introduces platform support for Encrypted Client Hello (ECH), a TLS extension that enhances user privacy by encrypting the Server Name Indication (SNI) in the TLS handshake. This encryption helps prevent network observers from easily identifying the specific domain your app is connecting to.
For apps targeting Android 17 (API level 37) or higher, ECH is used for TLS connections. ECH is active only if the networking library used by the app (for example, HttpEngine, WebView, or OkHttp) has integrated ECH support and the remote server also supports the ECH protocol. If ECH cannot be negotiated, the client sends an ECH extension with randomized contents (a mechanism called ECH GREASE). See RFC 9849 for more details on how ECH GREASE works.
To allow apps to customize this behavior, Android 17 adds a new
<domainEncryption> element to the Network Security Configuration file.
Developers can use <domainEncryption> within <base-config> or
<domain-config> tags to select an ECH mode (for example,
"enabled" or "disabled") on a global or per-domain basis.
For more information, see the Encrypted Client Hello documentation.
ต้องมีสิทธิ์เข้าถึงเครือข่ายภายในสำหรับแอปที่กำหนดเป้าหมายเป็น Android 17
Android 17 introduces the ACCESS_LOCAL_NETWORK runtime permission
to protect users from unauthorized local network access. Because this falls
under the existing NEARBY_DEVICES permission group, users who have already
granted other NEARBY_DEVICES permissions aren't prompted again. This new
requirement prevents malicious apps from exploiting unrestricted local network
access for covert user tracking and fingerprinting. By declaring and requesting
this permission, your app can discover and connect to devices on the local area
network (LAN), such as smart home devices or casting receivers.
Apps targeting Android 17 (API level 37) or higher now have two paths to maintain communication with LAN devices: Adopt system-mediated, privacy-preserving device pickers to skip the permission prompt, or explicitly request this new permission at runtime to maintain local network communication.
For more information, see the Local network permission documentation.
ซ่อนรหัสผ่านจากอุปกรณ์จริง
หากแอปกำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) ขึ้นไปและผู้ใช้กำลังใช้อุปกรณ์ป้อนข้อมูลจริง (เช่น แป้นพิมพ์ภายนอก) ระบบปฏิบัติการ Android จะใช้การตั้งค่า show_passwords_physical ใหม่กับอักขระทั้งหมดในช่องรหัสผ่าน โดยค่าเริ่มต้น การตั้งค่านั้นจะซ่อนอักขระรหัสผ่านทั้งหมด
ระบบ Android จะแสดงอักขระรหัสผ่านที่พิมพ์ล่าสุดเพื่อช่วยให้ผู้ใช้ทราบ ว่าพิมพ์รหัสผ่านผิดหรือไม่ อย่างไรก็ตาม แป้นพิมพ์ลัดเหล่านี้จะมีความจำเป็นน้อยกว่ามากเมื่อใช้กับแป้นพิมพ์ภายนอกขนาดใหญ่ นอกจากนี้ อุปกรณ์ที่มีแป้นพิมพ์ภายนอกมักมี จอแสดงผลขนาดใหญ่กว่า ซึ่งเพิ่มความเสี่ยงที่ผู้อื่นจะเห็นรหัสผ่านที่พิมพ์
หากผู้ใช้ใช้หน้าจอสัมผัสของอุปกรณ์ ระบบจะใช้การตั้งค่า
show_passwords_touchใหม่
การปกป้อง OTP สำหรับข้อความ SMS มาตรฐาน
ตั้งแต่ Android 17 เป็นต้นไป Android จะขยายการป้องกัน OTP ทาง SMS
ให้ครอบคลุมข้อความ SMS มาตรฐาน (ข้อความ SMS ที่มี OTP ซึ่งไม่ได้
ใช้รูปแบบ WebOTP หรือ SMS Retriever) สำหรับแอปส่วนใหญ่ที่กำหนดเป้าหมายเป็น
Android 17 (ระดับ API 37) ขึ้นไป ข้อความ SMS เหล่านี้จะ
พร้อมใช้งานหลังจากได้รับ 3 ชั่วโมง ความล่าช้านี้มีจุดประสงค์เพื่อช่วย
ป้องกันการลักลอบใช้ OTP ในระหว่างการหน่วงเวลา 3 ชั่วโมงนี้ ระบบจะระงับการออกอากาศของSMS_RECEIVED_ACTION และกรองการค้นหาฐานข้อมูลของผู้ให้บริการ SMS ข้อความ SMS จะพร้อมใช้งานในแอปเหล่านี้หลังจากที่เกิดความล่าช้า
แอปบางแอป เช่น แอปผู้ช่วย SMS เริ่มต้น แอปคู่หูของอุปกรณ์ที่เชื่อมต่อ ฯลฯ จะได้รับการยกเว้นจากความล่าช้านี้ แอปทั้งหมดที่ต้องอ่านข้อความ SMS เพื่อดึงข้อมูล OTP ควรเปลี่ยนไปใช้ SMS Retriever หรือ SMS User Consent API เพื่อให้ฟังก์ชันการทำงานยังคงดำเนินต่อไปได้
ความปลอดภัย
Android 17 มีการปรับปรุงความปลอดภัยของอุปกรณ์และแอปดังนี้
ความปลอดภัยของกิจกรรม
ใน Android 17 แพลตฟอร์มจะยังคงเปลี่ยนไปใช้สถาปัตยกรรม "ปลอดภัยโดยค่าเริ่มต้น" พร้อมเปิดตัวชุดการปรับปรุงที่ออกแบบมาเพื่อลดช่องโหว่ที่มีความรุนแรงสูง เช่น ฟิชชิง การลักลอบใช้การโต้ตอบ และการโจมตีแบบ Confused Deputy การอัปเดตนี้กำหนดให้นักพัฒนาแอปเลือกใช้ มาตรฐานความปลอดภัยใหม่โดยชัดแจ้งเพื่อรักษาความเข้ากันได้ของแอปและการปกป้องผู้ใช้
ผลกระทบที่สำคัญสำหรับนักพัฒนาแอปมีดังนี้
- การปิดช่องโหว่ BAL และการเลือกใช้ที่ปรับปรุงแล้ว: เรากำลังปรับปรุงข้อจำกัดการเปิดใช้กิจกรรมในเบื้องหลัง (BAL) โดยขยายการปกป้องไปยัง
IntentSenderนักพัฒนาแอปต้องย้ายข้อมูลออกจากค่าคงที่MODE_BACKGROUND_ACTIVITY_START_ALLOWEDรุ่นเดิม แต่คุณควร ใช้การควบคุมแบบละเอียด เช่นMODE_BACKGROUND_ACTIVITY_START_ALLOW_IF_VISIBLEซึ่งจำกัด การเริ่มต้นกิจกรรมไว้ในสถานการณ์ที่แอปโทรปรากฏให้เห็น ซึ่งจะช่วย ลดพื้นผิวการโจมตีได้อย่างมาก - เครื่องมือในการนำไปใช้: นักพัฒนาแอปควรใช้โหมดเข้มงวดและการตรวจสอบ Lint ที่อัปเดตแล้ว เพื่อระบุรูปแบบเดิมและเตรียมพร้อมสำหรับข้อกำหนดของ SDK เป้าหมายในอนาคต
เปิดใช้ CT โดยค่าเริ่มต้น
หากแอปกำหนดเป้าหมายเป็น Android 17 (API ระดับ 37) ขึ้นไป ระบบจะเปิดใช้ ความโปร่งใสของใบรับรอง (CT) โดยค่าเริ่มต้น (ใน Android 16 CT จะพร้อมใช้งาน แต่แอปต้องเลือกใช้)
DCL แบบเนทีฟที่ปลอดภัยยิ่งขึ้น - C
If your app targets Android 17 (API level 37) or higher, the Safer Dynamic Code Loading (DCL) protection introduced in Android 14 for DEX and JAR files now extends to native libraries.
All native files loaded using System.load() must be marked as read-only.
Otherwise, the system throws UnsatisfiedLinkError.
We recommend that apps avoid dynamically loading code whenever possible, as doing so greatly increases the risk that an app can be compromised by code injection or code tampering.
จำกัดฟิลด์ PII ในมุมมองข้อมูล CP2
สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) ขึ้นไป Contacts Provider 2 (CP2) จะจำกัดคอลัมน์บางรายการที่มีข้อมูลส่วนบุคคลที่ระบุตัวบุคคลนั้นได้ (PII) จากมุมมองข้อมูล เมื่อเปิดใช้การเปลี่ยนแปลงนี้ ระบบจะนำคอลัมน์เหล่านี้ออกจากมุมมองข้อมูลเพื่อเพิ่มความเป็นส่วนตัวของผู้ใช้ คอลัมน์ที่ถูกจำกัด ได้แก่
แอปที่ใช้คอลัมน์เหล่านี้จาก ContactsContract.Data
สามารถดึงข้อมูลจาก ContactsContract.RawContacts
แทนได้โดยการรวมกับ RAW_CONTACT_ID
บังคับใช้การตรวจสอบ SQL อย่างเข้มงวดใน CP2
สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (API ระดับ 37) ขึ้นไป
Contacts Provider 2 (CP2) จะบังคับใช้การตรวจสอบคำสั่ง SQL อย่างเข้มงวดเมื่อมีการเข้าถึงตาราง ContactsContract.Data โดยไม่มีสิทธิ์ READ_CONTACTS
การเปลี่ยนแปลงนี้จะทำให้ระบบตั้งค่าตัวเลือกStrictColumnsและ
StrictGrammarเมื่อค้นหาตาราง ContactsContract.Data หากแอปไม่มีสิทธิ์READ_CONTACTS
หากคำค้นหา
ใช้รูปแบบที่ไม่เข้ากันกับรูปแบบเหล่านี้ ระบบจะ
ปฏิเสธและทำให้เกิดข้อยกเว้น
การตรวจหา
Android 17 มีการเปลี่ยนแปลงต่อไปนี้ในด้านระบบอัจฉริยะ
การเลิกใช้งาน setContentCaptureEnabled
Content Capture is enabled by default on certain devices to allow on-device AI features to analyze screen contents for intelligent experiences.
Starting in Android 17, the
ContentCaptureManager.setContentCaptureEnabled(boolean)
API method is deprecated. For apps that target Android 17 (API level 37) or
higher, calling setContentCaptureEnabled(false) no longer disables Content
Capture.
If your app needs to continue disabling Content Capture or restrict screen
contents from being captured by the system, you must transition to using the
FLAG_SECURE window layout parameter.
To disable Content Capture, set the FLAG_SECURE flag on your window as shown
in the following example:
Kotlin
window.setFlags(
WindowManager.LayoutParams.FLAG_SECURE,
WindowManager.LayoutParams.FLAG_SECURE
)
Java
getWindow().setFlags(
WindowManager.LayoutParams.FLAG_SECURE,
WindowManager.LayoutParams.FLAG_SECURE
);
For more details, see the
WindowManager.LayoutParams.FLAG_SECURE reference
documentation.
สื่อ
Android 17 มีการเปลี่ยนแปลงลักษณะการทำงานของสื่อต่อไปนี้
การปิดช่องโหว่ของเสียงที่เล่นขณะล็อกหน้าจอ
ตั้งแต่ Android 17 เป็นต้นไป เฟรมเวิร์กเสียงจะบังคับใช้ข้อจำกัดในการโต้ตอบเสียงในเบื้องหลัง ซึ่งรวมถึงการเล่นเสียง คำขอโฟกัสเสียง และ API การเปลี่ยนระดับเสียง เพื่อให้มั่นใจว่าผู้ใช้เป็นผู้เริ่มการเปลี่ยนแปลงเหล่านี้โดยเจตนา
แอปทั้งหมดมีข้อจำกัดด้านเสียงบางประการ อย่างไรก็ตาม ข้อจำกัดจะเข้มงวดมากขึ้นหากแอปกำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) หากแอปเหล่านี้ โต้ตอบกับเสียงขณะที่อยู่ในเบื้องหลัง แอปต้องมีบริการที่ทำงานอยู่เบื้องหน้า นอกจากนี้ แอปต้องเป็นไปตามข้อกำหนดข้อใดข้อหนึ่งหรือทั้ง 2 ข้อต่อไปนี้
- บริการที่ทำงานอยู่เบื้องหน้าต้องมีความสามารถขณะใช้งาน (WIU)
- แอปต้องมีสิทธิ์การปลุกที่แน่นอนและโต้ตอบกับสตรีมเสียง
USAGE_ALARM
ดูข้อมูลเพิ่มเติม รวมถึงกลยุทธ์การลดความเสี่ยงได้ที่การเพิ่มความปลอดภัยของเสียงในเบื้องหลัง
รูปแบบของอุปกรณ์
Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงประสบการณ์ของผู้ใช้ ในอุปกรณ์ขนาดและรูปแบบต่างๆ
การเปลี่ยนแปลง API ของแพลตฟอร์มเพื่อไม่สนใจข้อจำกัดด้านการวางแนว ความสามารถในการปรับขนาด และสัดส่วนการแสดงผลบนหน้าจอขนาดใหญ่ (sw>=600dp)
เราได้เปิดตัวการเปลี่ยนแปลง Platform API ใน Android 16 เพื่อไม่สนใจข้อจำกัดด้านการวางแนว ความสามารถในการปรับขนาด และสัดส่วนการแสดงผลบนหน้าจอขนาดใหญ่ (sw >= 600dp) สำหรับแอปที่กำหนดเป้าหมายเป็น API ระดับ 36 ขึ้นไป นักพัฒนาแอปมีตัวเลือกในการเลือกไม่ใช้การเปลี่ยนแปลงเหล่านี้ ด้วย SDK 36 แต่ตัวเลือกการเลือกไม่ใช้นี้จะไม่มีให้บริการอีกต่อไป สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (ระดับ API 37) ขึ้นไป
ดูข้อมูลเพิ่มเติมได้ที่ระบบจะไม่สนใจข้อจำกัดเกี่ยวกับ การวางแนวและการปรับขนาด
การเชื่อมต่อ
Android 17 มีการเปลี่ยนแปลงต่อไปนี้เพื่อปรับปรุงความสอดคล้องและ
สอดคล้องกับInputStream มาตรฐานของ Java สำหรับซ็อกเก็ต RFCOMM ของบลูทูธ
ลักษณะการทำงานของ read() ใน BluetoothSocket สำหรับ RFCOMM ที่สอดคล้องกัน
สำหรับแอปที่กำหนดเป้าหมายเป็น Android 17 (API ระดับ 37) เมธอด read() ของ InputStream ที่ได้จาก BluetoothSocket ที่อิงตาม RFCOMM จะแสดงผลเป็น -1 เมื่อปิดซ็อกเก็ตหรือการเชื่อมต่อถูกตัด
การเปลี่ยนแปลงนี้จะทำให้ลักษณะการทำงานของซ็อกเก็ต RFCOMM สอดคล้องกับซ็อกเก็ต LE CoC และ
สอดคล้องกับเอกสารประกอบมาตรฐาน InputStream.read()
ซึ่งระบุว่าระบบจะแสดง -1 เมื่อถึงจุดสิ้นสุดของสตรีม
แอปที่อาศัยการดักจับ IOException เพียงอย่างเดียวเพื่อออกจากลูปการอ่านอาจได้รับผลกระทบจากการเปลี่ยนแปลงนี้ และควรอัปเดตลูปการอ่าน BluetoothSocket เพื่อตรวจสอบค่าที่ส่งคืนของ -1 อย่างชัดเจน ซึ่งจะช่วยให้มั่นใจได้ว่าลูปจะสิ้นสุดอย่างถูกต้องเมื่ออุปกรณ์ระยะไกลยกเลิกการเชื่อมต่อหรือปิดซ็อกเก็ต ดูตัวอย่างการติดตั้งใช้งานที่แนะนําได้ในข้อมูลโค้ดในคู่มือโอนข้อมูลผ่านบลูทูธ