{"slug": "github-says-its-ai-taskflows-found-24-android-vulnerabilities", "title": "GitHub says its AI taskflows found 24 Android vulnerabilities", "summary": "GitHub Security Lab reported finding and disclosing 24 vulnerabilities in Android applications using its open-source AI audit taskflows, according to a post dated September 28th and published September 29th by researcher Kevin Stubbings. The disclosed examples include an OsmAnd exported MapActivity flaw that GitHub says could let a malicious app trigger a settings import and infer viewed map tile coordinates, and a Wikipedia Android app hostname-parsing bug in its wikipedia:// deep links that could open an attacker-controlled page running JavaScript in the app's WebView. Running the mobile audit requires a Copilot license and premium model requests, and the taskflows are published in the seclab-taskflows repository for others to run.", "body_md": "# GitHub says its AI taskflows found 24 Android vulnerabilities\n\n**GitHub Security Lab says its open-source workflows found and reported 24 flaws. The examples include an OsmAnd location-tracking bug and a Wikipedia app deep-link issue; running the mobile audit requires a Copilot license and premium model requests.**\n\n        By [Ryan Merket](https://runtimewire.com/author/ryan-merket)\n        · Published \n\nPrimary source: [The GitHub Blog](https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/)\n\n## Why it matters\n\nA reusable audit workflow can help security teams examine mobile-specific attack surfaces that general code review may miss, including exported Android components and deep links. GitHub's examples also show the operational tradeoff: the workflows are inspectable and runnable, but depend on premium model requests and can consume significant time and tokens.\n\nGitHub Security Lab says it found and reported 24 vulnerabilities in Android applications using custom AI audit workflows. In a post dated September 28th and published September 29th, researcher [Kevin Stubbings](https://github.blog/author/kwstubbs/?ref=runtimewire) described two disclosed examples and published the taskflows for others to run. The report is GitHub Security Lab's account of a system it built, rather than an independent evaluation of its findings. [GitHub's account](https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/?ref=runtimewire)\n\nThe first example involves OsmAnd, a navigation app with more than 10 million Play Store downloads, [according to GitHub](https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/?ref=runtimewire). Its exported `MapActivity` accepts intent extras used when importing settings. Because another app can send arbitrary extras to an exported activity, GitHub says a malicious app could trigger an import without a notification or user confirmation, then replace settings that control map tiles. The attacker could route tile requests through a server they control and infer the coordinates of tiles the user viewed. GitHub also describes capturing route origins and destinations through the same issue. Its post says OsmAnd had three vulnerabilities; the location-tracking flaw is the one discussed in detail.\n\nThe second example concerns the Wikipedia Android app's `wikipedia://` deep links. GitHub says a hostname-parsing bug let a link open a non-Wikipedia URL inside the app, where an attacker-controlled page could run JavaScript in its WebView. The available text of the post cuts off while introducing a second code snippet about cookie handling. It does not provide enough information to verify the subsequent cookie and token-exposure chain or the stated testing limitations, so those details are not described here.\n\nThe taskflows are YAML-defined sequences of tasks run by GitHub Security Lab's agent framework. The framework gives each task a prompt and designated tools, and can pass results between tasks through a toolbox such as a memory cache. GitHub says each task starts with a fresh context, which makes task-by-task outputs easier to rerun while debugging. The framework itself is described in an [earlier GitHub Security Lab post](https://github.blog/security/community-powered-security-with-ai-an-open-source-framework-for-security-research/?ref=runtimewire); the companion [seclab-taskflows repository](https://github.com/GitHubSecurityLab/seclab-taskflows?ref=runtimewire) contains the example workflows and supporting MCP servers.\n\nFor the Android audit, Stubbings added `gather_mobile_entry_point_info.yaml` to separate mobile entry points from other entry points in a repository. He also modified `classify_application_local.yaml` to prompt the model to check for specified vulnerability classes in each entry point and component. For example, when a component uses an Android intent, the taskflow checks for issues such as a confused deputy or insecure broadcasts. GitHub says it runs both narrower, strict prompts and broader prompts multiple times, aiming to catch expected classes of bugs while leaving room for the model to identify other issues.\n\nTo try the mobile audit, start a Codespace from the [taskflows repository](https://github.com/GitHubSecurityLab/seclab-taskflows?ref=runtimewire), allow it to initialize, then run `./scripts/audit/run_mobile.sh myorg/myrepo` in the terminal. GitHub says a medium-sized repository can take an hour or two and that results open in an SQLite viewer; its post directs users to the `audit_results` table and rows marked in the `has_vulnerability` column. A Copilot license is required, and the prompts use premium model requests. The run can make many tool calls and consume substantial tokens.\n\nThe repository also documents local and container-backed execution requirements: Python 3.11 or later for local runs, Docker for taskflows that use container-backed tools, and configured AI API credentials and endpoint variables. Its README warns that audits can take several hours, especially on larger projects, and make enough AI requests to incur a non-trivial cost. GitHub's framework post describes the project as experimental and separates the agent implementation from the taskflow suite, so the workflows can be inspected and adapted rather than treated as a closed security scanner.", "url": "https://wpnews.pro/news/github-says-its-ai-taskflows-found-24-android-vulnerabilities", "canonical_source": "https://runtimewire.com/article/github-open-source-ai-taskflows-24-android-vulnerabilities", "published_at": "2026-09-29 07:48:05+00:00", "updated_at": "2026-09-29 08:17:51.800860+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools", "developer-tools", "artificial-intelligence"], "entities": ["GitHub", "GitHub Security Lab", "Kevin Stubbings", "OsmAnd", "Wikipedia Android app", "Copilot", "seclab-taskflows"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/github-says-its-ai-taskflows-found-24-android-vulnerabilities", "markdown": "https://wpnews.pro/news/github-says-its-ai-taskflows-found-24-android-vulnerabilities.md", "text": "https://wpnews.pro/news/github-says-its-ai-taskflows-found-24-android-vulnerabilities.txt", "jsonld": "https://wpnews.pro/news/github-says-its-ai-taskflows-found-24-android-vulnerabilities.jsonld"}}