GitHub’s AI agent found 24 Android app vulnerabilities
GitHub Security Lab's AI taskflows found 24 Android app vulnerabilities, including location tracking in OsmAnd and session-cookie theft in Wikipedia's app.
GitHub Security Lab researcher Kevin Stubbings built AI-driven audit workflows (taskflows) on the open-source Taskflow Agent and used them to report more than 20 Android app vulnerabilities. In OsmAnd, with over 10 million downloads, an exported MapActivity accepted restricted intent extras, letting any app silently swap the map tile source to an attacker server and log victims' coordinates. The Wikipedia Android app's deeplink handler used endsWith() for hostname checks, allowing attacker JavaScript in a trusted WebView and theft of session cookies valid across all Wikimedia projects. The AI over-flagged low-severity issues and misjudged real-world impact, so every finding still requires an expert human reviewer.