An open source agent examines mobile entry points, revealing server manipulation and cookie theft vulnerabilities, but findings require expert validation
An open-source AI security agent has uncovered 24 vulnerabilities in Android applications, including flaws that could allow covert location tracking and full account takeover.
Researcher Kevin Stubbings had built custom audit workflows, called taskflows, on top of GitHub Security Lab’s open-source Taskflow Agent framework, to find the vulnerabilities across multiple Android apps, according to a blog post published on 27 September 2026.
Rather than feeding an entire codebase to a model with a generic prompt, the taskflows break audits into narrower stages: one step identifies mobile-specific entry points such as exported activities, deep links, and broadcast receivers, while a second evaluates each entry point against a curated list of Android vulnerability classes.
List of flaws found
Among the most serious findings was a flaw in OsmAnd, a navigation app with more than 10m downloads. An exported activity called ‘MapActivity’ accepted intent extras that were meant to arrive only through an internal channel. Because Android provides no mechanism to restrict which extras an external caller can set, any app on the device — even one with no permissions — could silently import malicious settings, swap OsmAnd’s map-tile server for an attacker-controlled one, and log the coordinates of every tile the victim loaded, effectively tracking their location and routes without any visible change to the interface.
Another vulnerability chain affected the Wikipedia Android app. Its deep-link handler validated hostnames using an ‘endsWith()’ check, meaning a domain like ‘evil-wikipedia.org’ could pass as trusted and load attacker-controlled content inside the app’s WebView. A similarly weak check in the app’s cookie manager then leaked the victim’s long-lived Wikimedia session cookies to the attacker. Chained together, the two bugs enabled account takeover across every Wikimedia project — including Wikipedia, Commons, Wikidata, and Wikimedia Meta — after a single tapped link.
Stubbings has cautioned that the AI was better at finding vulnerabilities than at assessing their real-world impact. The model had repeatedly flagged low-severity issues even when instructed not to, and had misjudged cases where mitigating factors — such as internal storage overriding attacker-controlled external data — quietly neutralized an apparent exploit. Every finding still requires review by a researcher with mobile security expertise before it can be reported, according to Help Net Security.
The taskflows are publicly available through GitHub’s ‘seclab-taskflow-agent’ repository. Running them requires a GitHub Copilot license and can consume a large number of premium model requests, with audits of medium-sized repositories taking one to two hours.