📰 Full Story
Google has rolled out a QR-code based reCAPTCHA challenge as part of its Cloud Fraud Defense platform first announced on April 22, 2026, that requires users to scan a code with a “compatible” mobile device to prove they are human.
The verification flow accepts iOS devices and Android handsets running Google Play Services (reportedly version 25.41.30 or higher), but blocks or repeatedly challenges devices running privacy-focused, de‑Googled operating systems such as GrapheneOS, CalyxOS and other custom ROMs.
The change, which Google has been migrating to sites since late 2025, leverages hardware-backed attestation to verify device integrity and is designed to counter increasingly capable AI-driven bots.
Critics — including GrapheneOS developers, privacy advocates and parts of the security community — argue the move effectively ties basic web access to Google’s proprietary ecosystem, can exclude secure alternative OSes, and may have been rolled out automatically for many websites.
Workarounds for affected users include using a separate certified device or selecting fallback audio challenges, while some experts urge web administrators to consider alternative verification services to avoid locking out privacy‑focused users.
🔗 Based On
🕰️ The Story So Far: An Evolving Timeline
Monday, May 11, 2026 11:07 UTC
Google QR reCAPTCHA locks out privacy phones
Wednesday, May 6, 2026 11:56 UTC
Google expands Binary Transparency for Android apps








💬 Commentary