Google has released Android 17 QPR2 Beta 3 for supported Pixel devices, and the update introduces a new security feature designed to make call-forwarding fraud harder to carry out.
Google calls the change “Hardening against call forwarding fraud.” It adds restrictions to programmatic call-forwarding USSD requests and introduces an operating-system confirmation dialog when users manually dial supported call-forwarding codes.
The update was released on August 14, 2026, and includes the August 5, 2026 security patch.
What Is New in Android 17 QPR2 Beta 3?
The biggest security-related change in Beta 3 targets call-forwarding fraud.
Android can now identify and selectively restrict call-forwarding USSD codes, including codes such as *21*, when they are executed through the TelephonyManager.sendUssdRequest() API.
Google has added two main protections:
- API restrictions prevent standard apps from using
sendUssdRequest()for call-forwarding codes with only theCALL_PHONEpermission. - OS-level confirmation requires users to confirm a call-forwarding request when they manually dial a supported code through the system dialer.
How Android 17 QPR2 Beta 3 Helps Stop Call-Forwarding Scams
Call-forwarding scams often rely on social engineering.
A scammer may pretend to be from a bank, courier company, mobile carrier, or another trusted organization and convince a victim to dial a special phone code.
If the victim unknowingly activates call forwarding, incoming calls can be redirected to another number.
Android 17 QPR2 Beta 3 adds an extra layer of protection before this type of request can be completed.
1. Apps Cannot Freely Trigger Call-Forwarding USSD Codes
Previously, an app with the appropriate phone permission could use TelephonyManager.sendUssdRequest() to send USSD requests.
With Android 17 QPR2 Beta 3, standard apps cannot use this API to execute call-forwarding codes with only the CALL_PHONE permission.
When an app attempts a restricted request, Android can block it and return the USSD_ERROR_NOT_ALLOWED callback.
This makes it harder for an application to initiate call-forwarding changes without the required user involvement.
2. Android Adds a Confirmation Step
The second protection applies when the user manually enters a call-forwarding code through the system dialer.
Android 17 QPR2 Beta 3 can display an OS-level confirmation dialog before the call-forwarding command is executed.
This is particularly useful against social-engineering attacks.
If someone calls and tells you to dial a strange code, the confirmation screen gives you another opportunity to stop and reconsider the request.
What Happens to Other USSD Codes?
Google says the change is specifically focused on call-forwarding USSD requests.
Non-call-forwarding USSD functions remain unaffected. Google specifically gives examples such as mobile-money transactions and account checks.
That means the security change is not intended to disable legitimate USSD services.
Which Pixel Phones Can Get Android 17 QPR2 Beta 3?
Android 17 QPR2 Beta 3 is available for supported Pixel devices enrolled in the Android Beta Program.
The supported devices include:
- Pixel 6a
- Pixel 7, Pixel 7 Pro, Pixel 7a
- Pixel 8, Pixel 8 Pro, Pixel 8a
- Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a
- Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a
- Pixel Fold
- Pixel Tablet
The Android Emulator is also supported.
Android 17 QPR2 Beta 3 Build Numbers
Google lists two Beta 3 builds:
CP41.260731.005.A2CP41.260731.005.B1
The release date is August 14, 2026, and the security patch level is August 5, 2026.
How to Get Android 17 QPR2 Beta 3
If you have a supported Pixel phone, you can join the Android Beta Program and receive the beta through an over-the-air update.
Google also provides system images for developers and advanced users who want to manually install the beta.
For most users, the OTA route is the simpler option.
Important: Beta software is still pre-release software and may contain bugs or stability problems. Users who depend on their phone every day should consider this before installing a beta build.
What Developers Need to Know
The change is also important for Android developers.
Apps affected by the new restrictions should properly handle the USSD_ERROR_NOT_ALLOWED callback.
Google recommends that apps needing legitimate call-forwarding setup use the ACTION_DIAL intent when they do not qualify for an exempted role. This allows the app to pre-fill the dialer while giving the user control over the final action.
Other Fixes in Android 17 QPR2 Beta 3
The anti-scam protection isn’t the only change in Beta 3.
Google also fixed issues involving:
- Visual corruption and unexpected device restarts when opening the notification shade or Quick Settings.
- Incorrect battery-capacity degradation warnings shown by the Device Health and Support tool.
Android 17 QPR2 Beta 3 also brings other Pixel-focused changes, including expanded Dynamic Color theming, customizable Quick Settings layout, additional lock-screen blur effects, and a native App Lock feature.
Why This Android 17 Security Feature Matters
Call-forwarding fraud depends heavily on tricking people into performing an action they don’t fully understand.
The new Android protection doesn’t eliminate every possible form of telecom fraud, but it makes one important attack path more difficult.
Blocking restricted call-forwarding requests from standard apps reduces the possibility of background app abuse, while the confirmation dialog adds another barrier when a user manually enters a forwarding code.
Users should still avoid dialing unfamiliar USSD or MMI codes when instructed by an unexpected caller or message.
How to get the update
If you own a compatible Pixel device, you can join the Android Beta Program at google.com/android/beta to receive the OTA update. System images are also available for manual installation through the Android Flash Tool.
FAQ
What is Android 17 QPR2 Beta 3?
Android 17 QPR2 Beta 3 is the third beta release of Android 17’s second Quarterly Platform Release. Google released it on August 14, 2026, for supported Pixel devices and the Android Emulator.
What is the new Android 17 anti-scam feature?
The feature is designed to harden Android against call-forwarding fraud. It restricts programmatic call-forwarding USSD requests and adds an OS-level confirmation step when users manually initiate supported call-forwarding commands.
Does Android 17 block all USSD codes?
No. Google says non-call-forwarding USSD requests, including examples such as mobile-money transactions and account checks, are unaffected.
Does the protection work on Samsung and OnePlus phones?
Android 17 QPR2 Beta 3 is currently being distributed through the Pixel beta program. Other manufacturers’ rollout timing depends on their own Android 17 update schedules.
Do I need to enable the anti-scam feature manually?
No separate setting is described in Google’s release notes for enabling this protection. The restrictions and confirmation mechanism are part of Android 17 QPR2 Beta 3.
Can I still use call forwarding?
Yes. The change is intended to add restrictions and user confirmation around certain call-forwarding requests, rather than remove legitimate call-forwarding functionality.
Final Takeaway
Android 17 QPR2 Beta 3 is making call-forwarding scams harder to execute.
The update restricts programmatic call-forwarding USSD requests from standard apps and adds an OS-level confirmation dialog when users manually initiate supported call-forwarding commands.
For Android users, the most important takeaway is simple: don’t blindly dial codes requested by unexpected callers. Android’s new protection provides an additional safety layer, but user awareness remains an important part of scam prevention.
1 thought on “Android 17 QPR2 Beta 3 Adds New Anti-Scam Protection for Call Forwarding”