Android 17 QPR2 Beta 3 blocks programmatic call-forwarding fraud
Google introduces security restrictions on USSD codes in the latest Pixel beta to prevent scammers from hijacking calls.
Google has released Android 17 QPR2 Beta 3 for Pixel devices and the Android Emulator, introducing a critical security layer designed to combat telephony fraud. The update arrives as a late-stage refinement to the second quarterly platform release of the current development cycle.
The primary focus of this build is the implementation of security restrictions on programmatic call forwarding. According to 9to5Google, the system now parses and selectively restricts call-forwarding USSD codes—such as 21—when they are executed via the TelephonyManager.sendUssdRequest() API. This ensures that apps cannot silently redirect a user's calls without proper authorization or oversight.
The Role of QPR Updates
Quarterly Platform Releases (QPR) serve as Google's primary mechanism for delivering feature enhancements and critical bug fixes between major annual Android version launches. Android 17, codenamed 'Baklava,' is the current version under development. By utilizing the QPR cycle, Google can harden the operating system against emerging threats and refine the user experience without waiting for a full OS upgrade.
Hardening Against Fraud
This restriction of programmatic USSD codes represents a significant security hardening move for the Android ecosystem. By limiting the ability of third-party applications to trigger call forwarding, Google is mitigating a common attack vector used by scammers. Fraudsters often use these methods to hijack calls and SMS messages, which can be used to bypass two-factor authentication (2FA) and gain unauthorized access to sensitive user accounts.
Device Compatibility and Next Steps
The Beta 3 update is currently compatible with the Android Emulator and specific hardware, including the Pixel 10a and the Pixel 10 Pro Fold. As the QPR2 cycle nears completion, developers and beta testers should monitor how these API restrictions affect legitimate telephony applications. While the security benefits are clear, the industry will be watching to see if these restrictions lead to any regressions in app functionality before the final stable release rolls out to the general public.