{
  "id": 10514135,
  "title": "How we found 24 Android vulnerabilities using our open source AI security agent",
  "url": "https://urgent.news/2026/09/28/how-we-found-24-android-vulnerabilities-using-our-open-source-ai",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-28T19:00:00.000Z",
  "source": {
    "name": "GitHub Blog",
    "slug": "github-blog",
    "url": "https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/"
  },
  "original_language": "en",
  "account": "In a recent development in the realm of AI-powered security, researchers have uncovered 24 vulnerabilities in Android applications using a tool known as the GitHub Security Lab Taskflow Agent. The taskflows, which are open source and created by the team, enable security researchers to automate, package, and share AI prompts and workflows that enhance their work efficiency.\n\nThe discovery of these vulnerabilities was made possible through the use of custom taskflow prompts that guide AI models, allowing them to focus on specific classes of vulnerabilities in Android applications. By splitting research into incremental steps, the LLM can find complex vulnerabilities more rapidly, and potentially identify ones that would have gone unnoticed otherwise.\n\nOne of the vulnerabilities discovered involves a tracking mechanism in the OsmAnd third-party navigation app, which has over 10 million downloads. The taskflows identified a flaw in MapActivity, an exported activity that handles opening settings files and deeplinks within the app. This vulnerability enables malicious apps to send intents with arbitrary extras, which can be used to import settings undetected and track the user's location.",
  "summary": "A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app. The post How we found 24 Android vulnerabilities using our open source AI security agent appeared first on The GitHub Blog .",
  "key_points": [
    "Researchers discover 24 Android vulnerabilities using GitHub Security Lab Taskflow Agent",
    "Custom taskflow prompts guide AI models to focus on specific Android vulnerabilities",
    "Taskflows identify flaw in OsmAnd's MapActivity, enabling location tracking via malicious intents"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}