Help Net Security·4 min read·hard

GitHub's AI agent found 24 Android app vulnerabilities

A
Anamarija Pogorelec
GitHub's AI agent found 24 Android app vulnerabilities
✦AI Summary

GitHub Security Lab researcher Kevin Stubbings utilized custom AI-driven taskflows to identify 24 vulnerabilities in various Android applications. The study highlights both the effectiveness of AI in security auditing and its current limitations in assessing the severity of discovered bugs.

Why it matters

This demonstrates the evolving role of AI in cybersecurity and the ongoing need for human oversight in vulnerability management.

✦Dive DeeperCreate a free account to unlock

GitHub’s AI agent found 24 Android app vulnerabilities GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to find and report more than 20 vulnerabilities in Android apps.

Two of the disclosed bugs show what’s at stake. In OsmAnd, a navigation app with over 10 million downloads on the Play Store, an exported activity called MapActivity accepted intent extras that should have stayed restricted to an internal channel. Any app on the phone, no permissions needed, could use those extras to silently import malicious settings, including swapping OsmAnd’s map tile source for an attacker-controlled server. From there, the attacker could log the exact coordinates of every tile a victim loaded and reconstruct their routes, all without the user noticing anything had changed.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Also covering this story

One other newsroom covered this event. We read that version too.

technologyai
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in