deniz.in

Markets

Weather

Loading weather

· via GitHub Blog

GitHub's open-source AI security agent uncovers 24 Android flaws, including OsmAnd tracking bug

GitHub Security Lab says its open-source Taskflow Agent uncovered 24 Android vulnerabilities, including an OsmAnd flaw that lets any app silently track a user's location.

GitHub's open-source AI security agent uncovers 24 Android flaws, including OsmAnd tracking bug

GitHub's AI agent surfaces 24 Android vulnerabilities

GitHub Security Lab has described how an open-source AI agent it built, the Taskflow Agent, was used to uncover 24 vulnerabilities in Android applications. In a post on the GitHub Blog, a researcher on the team explains the Android-specific auditing workflows behind the findings and walks through one standout: a flaw in the navigation app OsmAnd that lets a malicious app silently track a user's location.

The Taskflow Agent is designed to help security researchers capture, package and share the AI prompts and workflows that prove effective in real audits. Instead of pointing a general-purpose model at a codebase and hoping for the best, taskflows split an audit into smaller, guided steps. According to the post, this helps a language model find complex vulnerabilities faster — or catch ones it would otherwise miss entirely.

Guided prompts aimed at mobile code

Two taskflows carry the Android-specific work. The first scans a repository for entry points — the places where data from outside the app can reach the code — and sorts them into mobile and non-mobile categories. That lets the agent run against repositories that mix mobile apps, web servers and desktop software while still reasoning about the correct attack surface.

The second changes how findings are classified, handing the model a list of established vulnerability classes to weigh against each entry point and component. Mobile vulnerability classes are less widely documented than their web counterparts, and language models are non-deterministic, so the fixed list keeps the model on essentials it might otherwise skip. For an intent-based entry point, for example, it checks for problems such as confused deputy behaviour and insecure broadcasts.

The post credits the pairing for the results: a strict, checklist-style prompt run repeatedly so obvious bugs are not overlooked, alongside a broader prompt that gives the model room to explore.

The OsmAnd flaw

The highlighted example involves OsmAnd, an OpenStreetMap-based navigation app with more than 10 million downloads on Android. The taskflows turned up three vulnerabilities in the app, and the post focuses on the one enabling location tracking, which has already been disclosed.

OsmAnd exports an activity called MapActivity, which handles opening settings files and deep links. Because the activity is exported, any other app on the device can launch it. The trouble lies in how settings imports work: the app reads values such as silent_import and replace from intent extras — key-value data attached to the launch request — even though Android offers no way to restrict which extras an external caller can set. Those values were intended to arrive via an AIDL service and should have travelled over an in-process channel.

By crafting an intent, a malicious app can import settings of its choosing without a notification, without user confirmation and with the option to overwrite existing settings. The demonstration changes the URL template OsmAnd uses to fetch map tiles so that requests go to an attacker-controlled server, which then returns the genuine OpenStreetMap tiles so nothing looks wrong. Every request leaks the coordinates of the tiles the user loads, handing the attacker a running picture of the victim's location. An app holding no permissions at all can do this, and the user sees no sign that anything changed.

Running it yourself

The taskflows are open source. Per the post, you start a codespace in the seclab-taskflows repository, wait a few minutes for it to initialise, then run the mobile audit script against an org and repository name. A medium-sized repository takes an hour or two; results land in an SQLite database, with findings listed in an audit_results table under a has_vulnerability flag. Two caveats: a GitHub Copilot license is required, the prompts consume premium model requests, and the volume of tool calls can burn through a large number of tokens.

Why it matters

This is disclosed, real-world output rather than a benchmark: 24 reported vulnerabilities, including three in an app with more than 10 million installs. It also demonstrates a workable pattern for AI-assisted security research — encoding domain expertise into repeatable, shareable prompt workflows that shore up what language models lack, namely consistency and coverage of niche vulnerability classes. Because the agent is open source, researchers and app maintainers can adapt the same workflows to their own code, in effect lowering the cost of an audit, provided they can absorb the token bill. And the OsmAnd bug is a reminder that exported components and unchecked intent extras remain a live class of Android weakness even in widely used apps.

  • #android
  • #security
  • #open-source
  • #ai-agents
  • #vulnerabilities
  • #github

Related posts