How we found 24 Android vulnerabilities using our open source AI security agent

GitHub Security Lab released open-source Android audit taskflows that guide AI agents to find vulnerabilities. The post details how these workflows identified over 20 flaws in Android applications. Developers can run the scripts in a codespace, though a Copilot license and premium model access are required. The tooling automates entry-point analysis and vulnerability detection.

Cover image for How we found 24 Android vulnerabilities using our open source AI security agent

The open‑source Android audit taskflows guided an LLM to locate more than 20 flaws across a range of apps, and the team ultimately reported 24 vulnerabilities in total. One disclosed issue involved an exported activity in the OsmAnd navigation app that accepted arbitrary intent extras, allowing a malicious program to import settings and silently track a device’s location. The flaw arises because the activity expects data from an internal service but instead trusts any external caller, a design error that gives attackers control over key parameters. Any Android application that exports activities without strict validation of incoming intent extras is potentially vulnerable, according to the researchers who built the taskflows. The OsmAnd case illustrates the risk for apps with millions of users; the Android version of OsmAnd has over 10 million downloads, meaning a large user base could be exposed. Developers of other mobile apps that rely on similar entry‑point patterns may also be at risk until they adopt stricter checks. The GitHub Security Lab recommends running the open‑source taskflows in a codespace, which requires a Copilot license and access to premium model requests, to automatically scan repositories for entry‑point weaknesses. After execution, reviewers should examine the SQLite audit results for rows marked as having a vulnerability and remediate any exported components that accept unchecked extras. Updating code to enforce internal communication channels or adding explicit intent‑filter restrictions can mitigate the identified threat.