The application Google Phone could soon alert users when a caller is impersonating one of their saved contacts.
A silent threat at the heart of phone scams
Caller ID spoofing, or caller number spoofing, is one of the most effective techniques in scammers' arsenal. The principle is simple: by manipulating the outgoing call identifier via Voice over IP systems, a fraudster can display any number on the victim's screen, including that of a friend, colleague, or bank. The person answers because they believe they recognize the caller. It is precisely this moment of trust that scammers exploit.
The scale of the problem is considerable. Spoofed calls are one of the main vectors for social engineering scams and financial fraud, generating around $980 million in annual losses worldwide, according to estimates. Despite industry initiatives like the STIR/SHAKEN protocol, designed to authenticate calls and initially deployed to combat robocallers, users continue to fall victim.
What the analysis of Google Phone code reveals
A teardown of version 222.0.913376317 of the Google Phone app, exclusive to Pixel devices, allowed Android Authority to uncover revealing code strings on May 18, 2026. These text fragments, integrated into the app's code but not yet publicly activated, precisely describe the behavior of a future feature for phone identity spoofing detection.
Among the identified strings is the message "This may not be %1$s", where the substitution parameter refers to the name of the contact saved in the user's directory. Another string indicates "Someone may be pretending to call from your contact’s number", while a final one offers an immediate action titled "Hang up". In short, the application would be able to display a visible alert during the call to signal that the caller's identity is likely falsified, and would allow hanging up with a single gesture.
The exact method Google would use to detect this spoofing in real-time is not specified in the analyzed code. This technical uncertainty is inherent to any teardown: these are ongoing works, which may evolve or never reach the general public in this form.
An anti-spoofing strategy that is gaining momentum
This discovery is part of a broader trend. About a month earlier, Android Authority had already highlighted the development of a feature called "Verified caller". Unlike the existing Verified Calls system, limited to the Google Phone app, this option would be deployed at the Android system level via Play Services, allowing for wider adoption, regardless of the phone application used. It would also support the detection of DNO (do-not-originate) numbers, i.e., numbers officially designated as never to be used for outgoing calls.
Google also officially announced on May 12, 2026, on its official blog, a distinct complementary feature: the verified financial calls. This system, developed in partnership with selected banks and financial institutions, works in the background when a banking app is installed and the user is logged in. When an incoming call appears to be from the bank, Android queries the app to verify if a call is actually in progress. If the app confirms that no call is being initiated from its end, the system automatically terminates the communication.
Google plans to roll out this feature on Android 11 devices and later, starting with partners Revolut, Itaú, and Nubank, before extending compatibility to other financial institutions later in the year.
Cutting-edge Pixel, but a challenge for the entire Android ecosystem
Pixel phone users already benefit from several layers of protection against malicious calls: call filtering, spam detection, and Call Screen, which allows you to ask the caller to identify themselves before you even pick up. Contact number spoofing detection would represent a further, targeted advancement, where current mechanisms remain more generic.
Eugene Liderman, Director of the Android Security and Privacy team at Google, stated in a post published on the company's official blog that the priority for the rest of 2026 is to evolve these intelligent defenses to make them even more transparent and powerful.
The trajectory is consistent: Google is gradually building a multi-layered system, ranging from generic spam detection to real-time verification of the caller's identity. The issue goes beyond Pixel devices, as features deployed via Play Services or integrated into Android 17 are intended to benefit the entire Android ecosystem, representing billions of active devices worldwide.
The fight against number spoofing is shaping up to be one of Android's major security initiatives in 2026. If the code strings discovered in Google Phone are confirmed, Pixel users could soon have an unprecedented safety net, directly during the ring, even before saying a word.




No comments! Be the first one.