GitHub Security Lab reported that targeted, AI-assisted taskflows identified and disclosed 24 Android vulnerabilities in open-source applications. The workflows direct an open-source AI security agent to map mobile attack surfaces, locate entry points such as exported components and deep links, and evaluate Android-specific flaw classes; researchers emphasized that analysts must still validate findings and build proof-of-concept exploits because LLM output can overstate impact or produce false positives.
In OsmAnd, an exported MapActivity accepted attacker-controlled intent extras that could silently import and replace application settings. A permissionless malicious app could use the issue to redirect map-tile or routing traffic and potentially infer a victim's location, routes, origin, and destination. In Wikipedia for Android, researchers found two inadequate hostname-suffix checks that could be chained through a wikipedia:// deep link to load attacker-controlled content, expose Wikimedia cookies, and enable account takeover across Wikimedia projects.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers found two hostname-suffix validation flaws in the Wikipedia Android app that could be chained through a wikipedia:// deeplink. The chain could load attacker-controlled WebView content, expose Wikimedia cookies, and enable account takeover across Wikimedia projects.
Researchers found that OsmAnd's exported MapActivity accepted sensitive settings-import intent extras from arbitrary apps rather than only its intended AIDL service. A permissionless malicious app could silently replace map-tile or routing endpoints with attacker-controlled servers, exposing location and route data.
GitHub Security Lab reported finding and disclosing 24 vulnerabilities in Android applications using its open-source Taskflow Agent and Android-focused AI auditing workflows.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.