GitHub AI Agent Uncovers 24 Android App Vulnerabilities
GitHub's AI audit agent found 24 Android flaws, including OsmAnd tracking and Wikipedia account takeover.
GitHub Security Lab disclosed 24 Android application vulnerabilities found with its open-source Taskflow Agent and mobile audit workflows. In OsmAnd, which has more than 10 million downloads, an exported MapActivity accepted settings-import intent extras, letting another app silently point map tiles at an attacker server that could infer location and routing. In the Wikipedia Android app, hostname checks using endsWith could accept domains such as evil-wikipedia.org, and a second weak cookie check could let attacker JavaScript in a WebView steal long-lived Wikimedia cookies and hijack accounts. GitHub said the AI findings still need expert validation because of false positives.