- Sources: primary, discussion
- Summary: Tim Perry of HTTP Toolkit documents that Android 17 requires certificate transparency by default for all system-trusted certificates, for apps targeting API level 37 running on an Android 17 device. Certificates issued by a locally generated CA carry no signed certificate timestamps, so they are rejected even though the CA sits in the system store, which breaks HTTPS interception for app debugging, security and privacy research, ad filtering, and enterprise traffic inspection with errors such as NET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED and NOT_ENOUGH_SCTS. The OS released in June 2026, Samsung Galaxy Z devices shipped with it in August, other OEMs began updating in early September, and API 37 becomes obligatory for Play Store publishing by August 2027.
- Why it matters: Every interception tool now has to reimplement the workaround Perry describes, deriving CT log operator identities from the CA certificate, embedding self-issued SCTs, and injecting the log operator config into the device.
- Follow-up: Track whether other interception tools ship the SCT workaround and whether Google offers a supported debugging path.
send feedback on this story