About this release
Trellix® Mobile Threat Defense (MTD) 5.10.x Android application release includes enhancements and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Rating
The rating defines the urgency for installing this update.
This release is recommended for all environments. Apply this update at the earliest convenience.
Release details
Release Date: July 21, 2026
For additional information about documentation and release details, visit the Customer Support Portal (login required).
End-of-Life details:
For information about the End-of-Life (EOL) dates for Trellix MTD versions, see Trellix Product End-of-Life Information.
New dynamically added threats
Refer to the Trellix Threat Reference Guide for the details on new and updated threats.
System requirements
The following lists the system requirements for this release of Trellix MTD:
The minimum OS version is Android 7.
Trellix MTD does not support Android 32-bit emulators.
For standard Samsung Knox device action support, Android version 7.x and Knox version 2.7 and later are required. For Samsung Knox MTD support, Knox version 3.3 and later are required.
New or changed
Android Deep Scan Forensic Analysis: This release introduces Android Deep Scan capabilities to improve visibility and ease of use.
The key features in this update are:
Forensic Analysis tile: The Trellix MTD app features a Forensic Analysis tile to indicate the deep scan capability of the device. This tile enables a deep scan analysis on the device. The scan determines a potential compromise and provides additional forensic information. After the scan completes, a summary of the security results is displayed.
Note
This feature requires Trellix MTD Console 5.38.x or later.
Dashboard functionality optimizations: The Trellix MTD app dashboard features a dynamic, interactive interface. This update improves scroll performance for smoother navigation. A tile organization selector menu allows sorting by Default, Severity, or Recently Used. An adaptive layout dynamically adjusts tile placement based on device behavior.
Enable or disable MTD App Reset feature: This feature allows you to enable or disable the display of the Reset button within the Advanced Troubleshooting section.
To enable this option:
Navigate to Policies → App Settings in the Trellix MTD Console.
Select the Enable App Reset Feature checkbox under Advanced Troubleshooting.
Note
This feature requires Trellix MTD Console 5.37.5 or later.
Enhanced URL Threat Forensics: This release updates phishing and Web Content Filtering (WCF) threats generated by the Web scanning feature in the Trellix MTD app. The Source field in Threat Forensic in the Trellix MTD Console precisely identifies the method used to enter a malicious URL into the Web scanning feature.
The updated Threat Forensic → Source values are:
User Entry - URL: The user manually types or pastes the URL into the Web tile in the Trellix MTD app.
QR Code: The user scans a QR code containing a URL using the Web tile in the Trellix MTD app.
These updated values are displayed in both the Threat Details of the Trellix MTD app and the Threat Forensic in the Trellix MTD Console. This update improves threat forensics and reporting.
App tile display enhancement: The App tile in the Trellix MTD app displays based on the Trellix MTD Console configuration. The tile appears when either of the following conditions is met:
Select the Enable the App Risk Lookup feature in MTD checkbox in Policies → App Settings in the Trellix MTD Console.
Select the option to enable app threats in Policies → Threat in the Trellix MTD Console.
Device trust for Android Enterprise: This feature enhances the device trust system in Android Enterprise. The system leverages new signals to analyze both managed and unmanaged devices. The Trellix MTD integration for device trust signals with the Android Management API is now enabled by default in Policies → App Settings in Trellix MTD Console 5.37.x or later for new policies and customer accounts. This configuration allows better device risk analysis and response.
The Trellix MTD app integration with the Android Management API for device trust signals requires you to install the Google-provided Android Device Policy app, which your IT administrator mandates for device security checks. This app is essential for the MTD integration. The installation process varies for devices:
Managed Devices: The EMM/MDM automatically installs the Android Device Policy application..
Unmanaged Devices: The system prompts you to install the Android Device Policy application during the Trellix MTD application installation if it is not present.
If you fail to install the Android Device Policy app after the initial prompt, it triggers Android Device Policy Not Installed threat within the Trellix MTD app if you enable the threat.
Go To Site button: The Go to Site button on the Web screen in the Trellix MTD app allows you to directly visit the safe websites.
AI-based phishing detections: This feature adds the Phishing Domains AI and Phishing Links AI subcategories to display AI-detected phishing domains and links and apply the appropriate phishing actions. These subcategories support machine learning-based phishing detection.
Note
This feature requires Trellix MTD Console 5.37.x or later.
Manage location permissions for Threat Zones tile: The Threat Zones tile features a location permission prompt to improve privacy. When you log on to the Trellix MTD enabled device, the Trellix MTD app requests a location permission only when you use the Threat Zones feature, and when the following conditions are met:
The admin console does not require location permissions.
Select the Danger Zone checkbox in Policies → App Settings in the Trellix MTD console.
You can manage location access from the Android system settings. If you deny location permission, a default location displays. This configuration ensures that the system accesses location data only when needed, which reduces unnecessary data collection.
UI support for Right-to-Left (RTL) languages: The Trellix MTD app includes an enhanced user interface for RTL languages, including Arabic and Hebrew. The alignment optimizations improve arrows, buttons, icons, and text to support the RTL layout. These improvements streamline navigation and enhance the user experience when the application uses RTL languages.
Manage event log settings: The Trellix MTD app updates the Full Event Log and the Activity Report. These features display tracking data across separate monitoring tabs. By default, All is selected in the Apps, Web, Device, Network, and Shortcuts tabs.
The system categorizes events into Active Issues and Resolved Issues to provide a clear view of security incidents. The system structures severity levels for these issues into Updates, Risks, and Threats with All selected by default in the tabs. Turn on notifications in the Settings to receive a summary of device protection activity.
You can also perform the below actions as required:
Sort threats by severity level: Use the sorting menu to organize threats by their severity levels, including Critical, Elevated, Low, or Normal. This option expands the existing capability to sort by Date and Time.
Select custom date range: Select a preferred date range, including 1 day, 1 week, 1 month, or 3 months, to view statistics. The report displays the selected date range and the number of scans completed
Resolved issues
This release resolves the general stability issues.