GitHub AI Security Agent Flags 24 Android Vulnerabilities in Popular Apps
GitHub says its open-source AI security agent found 24 vulnerabilities in Android apps, offering a concrete example of AI-assisted bug hunting turning up real issues in widely used mobile software. In a Sept. 28 blog post, Kevin Stubbings of GitHub Security Lab wrote, “At the time of writing this blog, we found 24 Android vulnerabilities in mobile applications.” The post highlighted examples involving the OsmAnd navigation app and the Wikipedia Android app.
The claim matters because it moves the discussion around AI security tools from theory to a specific set of findings in real apps. It also comes with an important limit: GitHub says the tooling can help surface likely bugs, but people still need to review them for false positives, real-world exploitability and severity. GitHub Security Lab is GitHub’s vulnerability research and coordinated disclosure team, which has published advisories for open-source projects since 2019.
In the OsmAnd example, GitHub said an exported Android component called MapActivity could be abused through an Intent — a standard Android messaging mechanism that lets apps trigger actions in other apps. According to the post, an attacker could use that path to import attacker-controlled settings, including overwriting map tile URLs. GitHub said the result could expose sensitive location-related data, such as precise tile coordinates, routes and trip origins or destinations, even from an app that does not need extra permissions.
The Wikipedia example described a different but familiar mobile risk: flaws in deeplink and WebView handling. A deeplink is a link that opens a specific location inside an app, while a WebView is the embedded browser window many apps use to display web content. GitHub said a problem in the app’s handling of wikipedia:// links, combined with a cookie domain-check issue, could allow an attacker to load a non-Wikipedia page inside the app’s WebView and receive long-lived Wikimedia cookies. According to the post, that could enable account takeover across Wikimedia projects.
The research is tied to GitHub Security Lab’s Taskflow Agent, an open-source framework the company introduced in January for AI-assisted security research. GitHub said both the agent and example taskflows are publicly available, and that readers can use the same tooling on their own applications. As Stubbings wrote, “The seclab-taskflow-agent will help you get started with security in a couple minutes and is open to contributions for those who find interesting and unique prompts, tools and mechanisms for finding vulnerabilities with AI.”
Even so, GitHub’s own write-up stressed that large language models appear stronger at identifying suspicious code paths than at judging how serious a bug is. In practice, that means the systems may flag issues that are not exploitable, or misread how much harm a flaw could cause. Human judgment is still needed to decide whether a finding is a meaningful vulnerability and how it should be disclosed.
That caveat also applies to the status of the two example cases. GitHub Security Lab’s post points readers to its advisories page for coordinated disclosures, but at the time of this reporting, the lab’s public advisories index did not show advisory pages specifically naming OsmAnd or Wikipedia for these examples. The research material reviewed also did not include GHSL IDs, CVEs or vendor patch details for either case.