GitHub's AI agent found 24 Android app vulnerabilities
GitHub Security Lab researcher Kevin Stubbings used custom AI-driven audit workflows built on the open source Taskflow Agent to find and report more than 20 vulnerabilities in Android apps, including OsmAnd and the Wikipedia app. In OsmAnd, any app could silently swap the map tile source and log a victim's coordinates; in Wikipedia, a flawed hostname check exposed session cookies.
- OsmAnd's exported MapActivity let any app redirect map tiles and log user coordinates
- Wikipedia app's endsWith() hostname check allowed evil-wikipedia.org to load in WebView
- A second cookie-manager flaw leaked long-lived Wikimedia session tokens
- AI finds bugs well but misjudges severity, so human mobile reviewers are still required
Read next
Security