GitHub Security Lab's AI taskflows uncover 24 Android vulnerabilities, including OsmAnd location tracking and Wikipedia account-takeover chains
Open-source Taskflow Agent audit workflows built by researcher Kevin Stubbings led to 24 reported Android app vulnerabilities: OsmAnd (10M+ downloads) flaws allow silent settings import and location tracking, while Wikipedia deeplink and cookie flaws enable…
GitHub Security Lab (blog post dated 2026-09-28) disclosed 24 vulnerabilities in Android applications found with staged, Android-specific audit workflows ('taskflows') built on the open-source Taskflow Agent by researcher Kevin Stubbings; Report 2's body phrases the count as 'more than 20.' The prompts separate mobile entry points and direct the model toward bug classes such as confused deputy and insecure broadcasts. In OsmAnd, which has more than 10 million downloads, an exported MapActivity accepted intent extras meant for an internal service, letting another app silently import settings and swap the map tile source to an attacker-controlled server that can log victims' coordinates, infer location, and reconstruct routes. In the Wikipedia Android app, a wikipedia:// deeplink handler used endsWith() for hostname checks, accepting lookalike domains such as evil-wikipedia.org and allowing attacker JavaScript in a trusted WebView; a second weak cookie check let that JavaScript steal long-lived session cookies valid across all Wikimedia projects, and per Reports 3 and 4 the chained bugs could expose Wikimedia usernames and authentication tokens, enabling account takeover after one malicious link. The model over-flagged low-severity issues and misjudged real-world impact, so every finding requires an expert human mobile-security reviewer. Running the audits requires a GitHub Copilot license and consumes many premium model requests (Report 1 says 'many tokens'), and the workflows are public/open source for Copilot users. No report states that any of the flaws are being exploited.
- GitHub Security Lab disclosed 24 Android app vulnerabilities found via staged, Android-specific audit workflows ('taskflows') on the open-source Taskflow Agent; researcher Kevin Stubbings built the workflows (Report 2's body says 'more…
- Blog post dated 2026-09-28; secondary coverage published 2026-09-29.
- The workflows separate mobile entry points and direct the model toward bug classes such as confused deputy and insecure broadcasts.
- OsmAnd (more than 10 million downloads): an exported MapActivity accepted intent extras meant for an internal service, allowing another app to silently import settings and redirect map tiles and routing to an attacker-controlled server…
- Wikipedia for Android: a wikipedia:// deeplink handler used endsWith() hostname checks, accepting lookalike domains such as evil-wikipedia.org, letting attacker JavaScript run in a trusted WebView.
- A second weak cookie check in the Wikipedia app let attacker JavaScript steal long-lived session cookies valid across all Wikimedia projects; chained with the hostname flaw, this could expose Wikimedia usernames and authentication tokens…
- The model over-flagged low-severity issues and misjudged real-world impact, so every finding requires an expert human mobile-security reviewer; GitHub says results need validation due to false positives.
- The workflows are public/open source, but running them requires a GitHub Copilot license and consumes many premium model requests (Report 1: 'many tokens').
Coverage timelineoldest first · each row is one article
- · 1d agoHow we found 24 Android vulnerabilities using our open source AI security agent
GitHub Blog · Security· 61
GitHub Security Lab’s AI taskflows uncovered 24 Android bugs, including OsmAnd location tracking.
- · 21h agoGitHub’s AI agent found 24 Android app vulnerabilities
Help Net Security· 55
GitHub Security Lab's AI taskflows found 24 Android app vulnerabilities, including location tracking in OsmAnd and session-cookie theft in Wikipedia's app.
- · 16h ago