Independent tech intelligence, checked against primary sources.

TechPulseMind Useful technology.
No manufactured hype.

GitHub’s Open Source AI Agent Finds 24 Android Vulnerabilities

GitHub's open source Taskflow Agent found 24 Android vulnerabilities, including location tracking in OsmAnd and an account takeover in the Wikipedia app.

GitHub’s Open Source AI Agent Finds 24 Android Vulnerabilities

GitHub’s Security Lab has reported 24 vulnerabilities in Android applications using an open source AI agent it calls the Taskflow Agent, according to a blog post published September 28 by security researcher Kevin Stubbings. The findings include a location-tracking flaw in the OsmAnd navigation app and an account takeover in the Wikipedia Android app.

The Taskflow Agent, announced by GitHub, lets security researchers automate, package and share the AI prompts and workflows they use for their work. Stubbings wrote that he built auditing taskflows specifically for Android apps, splitting the research into incremental steps so the model can find complex vulnerabilities faster or catch ones it would otherwise miss.

Two disclosed flaws show the impact

OsmAnd, a navigation app with more than 10 million downloads on Android, exports an activity called MapActivity that handles settings files and deeplinks. According to the post, the app accepts intent extras for settings imports, including silent import, replace and settings types, and Android offers no way to restrict which extras an external caller can set. Because the activity is exported, any app can send it an intent and import settings undetected.

Stubbings described how an attacker could overwrite the default map tile files with a URL pointing to their own server, leaking the exact x, y coordinates of every tile a user loads. The same technique can capture the origin and destination of every route a user takes, he wrote, without any change the user would notice.

In the Wikipedia Android app, a logic bug in the hostname parser lets a wikipedia:// deeplink load non-Wikipedia URLs. A second issue in the app’s cookie handling checks whether a page should receive cookies from wikipedia.org using a domain suffix match. Chained together, the two bugs let an attacker show a page ending in wikipedia.org, such as evil-wikipedia.org, and receive the user’s long-lived token and session token valid across every Wikimedia project.

Where the agent still needs a human

Stubbings wrote that the AI is good at finding vulnerabilities but struggles to estimate their severity, sometimes reporting low-impact issues or flagging problems that require states unlikely in real use. Mitigating factors, such as data from internal storage taking priority over attacker-controlled external storage, can lead to false positives, he added. Each finding, in his view, should be reviewed by a security researcher who knows mobile applications.

He was more positive about the model’s grasp of API behavior across languages, noting that most proof-of-concept code it produced needed little modification.

How to run the taskflows yourself

The taskflows are open source. GitHub says a GitHub Copilot license is required, the prompts use premium model requests, and a run can consume a large number of tokens. To try them, open the seclab-taskflows repository and start a codespace, wait for it to initialize, then run ./scripts/audit/run_mobile.sh myorg/myrepo in the terminal. GitHub notes a run can take an hour or two on a medium-sized repository, after which an SQLite viewer opens with the results in the “audit_results” table.

Sources

Some links on this page may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. See our affiliate disclosure.