GitHub's AI agent finds 24 Android app flaws
GitHub Security Lab says its open-source taskflow agent uncovered 24 vulnerabilities in Android apps, including a location-tracking bug in OsmAnd and an account-takeover flaw in Wikipedia's app.
GitHub's Security Lab said its open-source "taskflow" agent found 24 vulnerabilities across Android apps. One critical bug was in OsmAnd, an app with more than 10 million downloads. The flaw let a malicious app track a device's location and pull its route data. The lab also credited the agent with an account-takeover flaw in the Wikipedia Android app, tied to a hostname-parsing error in how it handles deep links.
The agent works by splitting a security review into a sequence of custom-prompted steps, GitHub said. That differs from asking a model to scan a whole codebase in one pass. The prompts are tuned for mobile entry points and vulnerability classes specific to Android. A GitHub researcher wrote in the post that "LLMs can find logic vulnerabilities with critical impact, not just generic bug classes."
GitHub published the agent as the seclab-taskflows repository. Anyone with a Copilot licence can run it against their own codebase from a GitHub Codespace, using a single script, GitHub said. A medium-sized repository takes one to two hours to audit and consumes a significant number of premium model requests, GitHub said.
The Wikipedia and OsmAnd bugs are logic flaws, the kind automated scanners typically miss. They depend on how an app's own code handles unexpected input, not on a known unsafe function. GitHub did not say whether either app's maintainers have already shipped fixes.