GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws
GitHub’s AI security agent found 24 Android flaws, including OsmAnd tracking and Wikipedia account takeover.
GitHub Security Lab said its open-source Taskflow Agent identified 24 vulnerabilities in Android applications using staged, Android-specific audit workflows. In OsmAnd, which has more than 10 million downloads, an exported MapActivity could let a malicious app silently import settings, redirect map and routing requests, and infer a user’s location. In Wikipedia for Android, weak hostname checks on a wikipedia:// deep link and cookie handling could load an attacker page in a WebView and expose Wikimedia usernames and authentication tokens, enabling account takeover. GitHub said large language model findings still require expert validation, and the workflows are public for GitHub Copilot users.