GitHub AI Agent Uncovers 24 Android App Vulnerabilities
GitHub's AI audit agent found 24 Android flaws, including OsmAnd tracking and Wikipedia account takeover.
GitHub Security Lab disclosed 24 Android application vulnerabilities found with its open-source Taskflow Agent and mobile audit workflows. In OsmAnd, which has more than 10 million downloads, an exported MapActivity accepted settings-import intent extras, letting another app silently point map tiles at an attacker server that could infer location and routing. In the Wikipedia Android app, hostname checks using endsWith could accept domains such as evil-wikipedia.org, and a second weak cookie check could let attacker JavaScript in a WebView steal long-lived Wikimedia cookies and hijack accounts. GitHub said the AI findings still need expert validation because of false positives.
- GitHub Security Lab disclosed 24 Android flaws found with an AI taskflow agent.
- OsmAnd's exported MapActivity can silently accept attacker-supplied settings.
- A malicious tile server can infer location from requested map coordinates.
- Wikipedia deeplinks using endsWith can treat attacker domains as trusted.
- Chained WebView and cookie flaws could hijack Wikimedia accounts.
Full article647 words · extracted from gbhackers.com · click to collapse
GitHub Security Lab has disclosed 24 vulnerabilities in Android applications discovered through its open-source AI security agent and specialized audit taskflows.
The findings highlight issues that could enable covert location tracking in the OsmAnd navigation app and account takeover attacks against Wikipedia users on Android.
Kevin Stubbings, a researcher at GitHub Security Lab, developed targeted taskflows for the lab’s Taskflow Agent, which is an AI-assisted framework designed to automate repetitive security research workflows.
Instead of asking a model to audit an entire codebase, these workflows break the auditing process into smaller stages. This approach allows the model to identify application entry points, map Android-specific attack surfaces, and evaluate relevant vulnerability classes.
24 Android App Vulnerabilities
The Android taskflows address mobile-specific risks that generic code-review prompts might overlook. One taskflow, named `gather_mobile_entry_point_info.yaml`, isolates mobile entry points from web, desktop, and other components in mixed repositories.
Another workflow, `classify_application_local.yaml`, prompts the model to examine known Android weakness patterns based on the affected component.
For intent-driven entry points, the model investigates insecure broadcasts, confused-deputy conditions, attacker-controlled intent extras, exported components, unsafe deep-link parsing, WebView flaws, and exposed JavaScript bridges.
GitHub combined strict, repeatable prompts with broader exploratory runs. The structured prompts helped ensure essential checks ran consistently, while the open-ended analysis let the AI identify non-obvious logic flaws and exploit chains.
One significant issue was found in OsmAnd, an Android navigation application with over 10 million downloads. GitHub identified an exported component, `MapActivity`, that accepted sensitive settings-import parameters through intent extras.
The application expected fields such as `silent_import`, `replace`, and `settings` type values to come from an internal AIDL service.
However, because the activity was exported, another app could supply arbitrary extras upon launching it. This vulnerability allowed a malicious app, potentially without requiring special permissions, to silently import and replace OsmAnd’s configuration.
An attacker could change the app’s default map-tile source to an attacker-controlled server. By returning legitimate map tiles while logging the requested tile coordinates, the server could infer the victim’s location. This same abuse path could also reveal routing-related information, including a user’s likely origin and destination, without visibly altering the app’s interface.
Wikipedia Deeplink Takeover Chain
GitHub also reported a vulnerability chain in the Wikipedia Android app. The app registered the `wikipedia://` scheme to open content within the application, but its deeplink handler used a hostname suffix check based on the `endsWith()` function.
This logic could mistakenly accept an attacker-owned domain ending in `wikipedia.org`, such as `evil-wikipedia.org`, instead of requiring an exact trusted hostname. As a result, a malicious deeplink could load attacker-controlled content in the app’s WebView, while making it appear as though the interaction originated from Wikipedia.
Researchers identified a second similarly weak hostname check in the app’s cookie-management logic. When chained, these flaws could let an attacker trigger the deeplink, execute JavaScript in the app’s WebView, obtain long-lived Wikimedia cookies, and potentially hijack accounts across Wikimedia services, including Wikipedia, Commons, Wikidata, and Meta.
GitHub emphasized that AI-generated findings still require expert validation. While the models were effective at recognizing API behavior and identifying potential exploit paths, they also produced false positives. They sometimes overestimated severity by overlooking mitigating controls or complex application logic.
For maintainers, the key takeaway is that AI taskflows can enhance code-auditing coverage, especially for recurring Android attack surfaces. Still, they should complement, not replace, manual exploitation testing, threat modeling, and security reviews.
The taskflows are available in GitHub Security Lab’s open-source repository. Users can launch a Codespace and run `./scripts/audit/run_mobile.sh myorg/myrepo`. GitHub notes that a Copilot license and premium model requests are required, and larger repositories may take one to two hours to audit.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.