GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


GitHub Security Lab has disclosed that its open-source AI security agent identified 24 vulnerabilities in Android applications, including flaws that could enable covert location tracking in OsmAnd and account takeover attacks against Wikipedia for Android.

The findings highlight how targeted AI workflows can help researchers uncover complex mobile logic flaws, while still requiring human validation.

The research used the GitHub Security Lab Taskflow Agent, an open-source framework designed to automate and share AI-assisted security research workflows.

Rather than asking a large language model to scan an entire repository with a general prompt, researchers created Android-specific taskflows that broke audits into smaller stages.

One taskflow identifies mobile entry points, such as exported activities, services, broadcast receivers, and deep links. Another taskflow assesses each entry point against Android-focused vulnerability classes, including insecure intents, confused deputy problems, unsafe broadcasts, cross-app scripting, and WebView risks.

This structure helps the AI understand the relevant attack surface in repositories that may contain mobile, web, and desktop code.

GitHub AI Finds 24 Android Vulnerabilities

One of the most serious findings affected OsmAnd, an Android navigation application with more than 10 million downloads. Researchers found that the app’s exported MapActivity accepted security-sensitive intent extras while importing settings.

Because exported Android activities can receive intents from other applications, a malicious app could supply attacker-controlled values such as silent_import, replace, and export_type_list_key.

The vulnerable logic allowed an unprivileged malicious application to silently import and replace OsmAnd settings without alerting the user. An attacker could modify the application’s map-tile source so that map requests were sent to an attacker-controlled server.

By logging tile coordinates, the attacker could infer a victim’s location and movements. The same weakness could also expose routing requests, including route origins and destinations. At the same time, the user continued using the application normally.

GitHub also detailed an account takeover chain in the Wikipedia Android application. The app registers a wikipedia:// deep link handler to open content inside its WebView. However, the hostname validation used an endsWith() check instead of validating the exact trusted domain.

This allowed a malicious domain such as evil-wikipedia.org to satisfy the suffix check because its name ends with wikipedia.org. An attacker could create a malicious webpage containing a crafted deep link and persuade a victim to open it.

The Wikipedia app could then load attacker-controlled content inside its WebView, potentially making the victim believe they were viewing a legitimate Wikipedia page.

A second domain-suffix validation issue in the application’s cookie-handling code made the attack more severe. The flawed check could cause the WebView to provide Wikimedia cookies to the attacker-controlled page.

Researchers said the stolen data could include a username, long-lived authentication token, and session token valid across Wikimedia projects, including Wikipedia, Wikimedia Commons, Wikidata, and Meta. Chaining the two bugs could therefore result in account takeover after a victim taps a single malicious link.

GitHub cautioned that AI-generated findings must not be accepted without expert review. Large language models can identify code patterns and relevant APIs effectively. However, they can also misjudge severity, overlook mitigating behavior, or generate false positives.

Researchers found that requiring the model to build a proof of concept can improve triage, although human testing remains essential.
The Taskflow Agent and Android audit workflows are publicly available.

GitHub said users need a GitHub Copilot license, and audits can consume substantial premium-model requests because medium-sized repositories may take one to two hours and require many tool calls. The results are stored in an SQLite audit_results table for researcher review.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws appeared first on Cyber Security News.