<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf" -->

---
title: How we found 24 Android vulnerabilities using our open...
description: GitHub Security Lab describes how it built custom AI taskflow prompts on top of its open-source Taskflow Agent to hunt for Android-specific vulnerability...
canonical: https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: How we found 24 Android vulnerabilities using our open source AI security agent | daily.dev
og:description: GitHub Security Lab describes how it built custom AI taskflow prompts on top of its open-source Taskflow Agent to hunt for Android-specific vulnerability...
og:url: https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf
og:image: https://api.daily.dev/og/posts/rqG6oSWxF.png
og:image:alt: How we found 24 Android vulnerabilities using our open source AI security agent
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How we found 24 Android vulnerabilities using our open source AI security agent

**[GitHub Blog](https://daily.dev/sources/ghblog)** · 12 min read · 2 upvotes · 0 comments

## Summary

GitHub Security Lab describes how it built custom AI taskflow prompts on top of its open-source Taskflow Agent to hunt for Android-specific vulnerability classes, resulting in 24 reported bugs. The post details two disclosed findings: a location-tracking vulnerability in OsmAnd via an exported activity accepting attacker-controlled intent extras, and a Wikipedia Android app deeplink parsing bug enabling account takeover through cookie theft and WebView JavaScript execution. It also reflects on LLM strengths (deep API and exploit knowledge) and weaknesses (poor severity estimation, false positives) in security research, and gives instructions for running the open-source taskflows against your own repo.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent>

## Questions this post answers

### How did attackers exploit OsmAnd's exported MapActivity to track user location?

OsmAnd's exported MapActivity accepted intent extras like settings_version, silent_import, replace, and export_type_list_key that were meant to only come from an internal AIDL service. Because any app can set arbitrary extras on an exported activity's intent, an attacker could silently import malicious settings that replaced map tile URLs with an attacker-controlled domain, leaking the exact coordinates of every tile and route the user loaded.

_Developers auditing exported Android components can track findings like this OsmAnd case on daily.dev._

### What was the Wikipedia Android app deeplink vulnerability that enabled account takeover?

A logic bug in the hostname parser for the wikipedia:// deeplink scheme only checked that the authority ended with the base domain, so an attacker-controlled URL like evil-wikipedia.org passed validation. Combined with a similar flaw in the cookie manager that checked domain.endsWith(domainSpec), attackers could load a spoofed page inside the app's WebView and steal long-lived Wikimedia session cookies, giving full account takeover.

_Mobile developers reviewing deeplink and WebView cookie handling can follow findings like this on daily.dev._

### What are the limitations of using LLMs to find and assess Android security vulnerabilities?

LLMs are effective at finding logic vulnerabilities and understanding API behavior across languages, but they struggle at estimating severity accurately, often reporting low-impact bugs even when told not to and missing mitigating factors like internal storage overwriting attacker-controlled external storage data in path traversal cases. Explicit prompting for proof-of-concept creation and human researcher review are needed to filter false positives.

_Teams weighing AI-assisted security tooling against manual review can follow this tradeoff discussion on daily.dev._

## Similar posts on daily.dev

- [How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework](https://daily.dev/posts/how-to-scan-for-vulnerabilities-with-github-security-lab-s-open-source-ai-powered-framework-qezcyia5u) · GitHub Blog · 1 upvotes · 0 comments
- [This Week In Security: Android Exposes ADB, ShinyHunters Get Paid, Robot Dogs, And More](https://daily.dev/posts/this-week-in-security-android-exposes-adb-shinyhunters-get-paid-robot-dogs-and-more-nxdkbbxku) · Hackaday · 0 upvotes · 0 comments
- [One-Click Account Takeover via Deep Link Token Auto-Append](https://daily.dev/posts/one-click-account-takeover-via-deep-link-token-auto-append-xwkhmw1s6) · InfoSec Write-ups · 0 upvotes · 0 comments
- [OWASP Mobile Top 10 for Android – How AutoSecT Detects Each Risk?](https://daily.dev/posts/owasp-mobile-top-10-for-android-how-autosect-detects-each-risk--fnqcmykal) · Security Boulevard · 1 upvotes · 0 comments
- [Why Your Deep Links Might Be a Backdoor](https://daily.dev/posts/why-your-deep-links-might-be-a-backdoor-upozvysop) · ProAndroidDev · 0 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#github](https://daily.dev/tags/github), [#android](https://daily.dev/tags/android), [#vulnerability](https://daily.dev/tags/vulnerability), [#appsec](https://daily.dev/tags/appsec)

[View this post on daily.dev](https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"How we found 24 Android vulnerabilities using our open source AI security agent","url":"https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf"},"datePublished":"2026-09-28T19:04:42.730Z","dateModified":"2026-09-28T19:05:14.888Z","description":"GitHub Security Lab describes how it built custom AI taskflow prompts on top of its open-source Taskflow Agent to hunt for Android-specific vulnerability...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2f882e6bc51b680d2f7f63214db30b40?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/2f882e6bc51b680d2f7f63214db30b40?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"GitHub Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"GitHub Blog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/106cf162b88840808484d4b5429b59b1","url":"https://daily.dev/sources/ghblog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,github,android,vulnerability,appsec","timeRequired":"PT12M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"GitHub Blog","item":"https://daily.dev/sources/ghblog"},{"@type":"ListItem","position":3,"name":"How we found 24 Android vulnerabilities using our open source AI security agent"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent-rqg6oswxf#faq","mainEntity":[{"@type":"Question","name":"How did attackers exploit OsmAnd's exported MapActivity to track user location?","acceptedAnswer":{"@type":"Answer","text":"OsmAnd's exported MapActivity accepted intent extras like settings_version, silent_import, replace, and export_type_list_key that were meant to only come from an internal AIDL service. Because any app can set arbitrary extras on an exported activity's intent, an attacker could silently import malicious settings that replaced map tile URLs with an attacker-controlled domain, leaking the exact coordinates of every tile and route the user loaded. Developers auditing exported Android components can track findings like this OsmAnd case on daily.dev."}},{"@type":"Question","name":"What was the Wikipedia Android app deeplink vulnerability that enabled account takeover?","acceptedAnswer":{"@type":"Answer","text":"A logic bug in the hostname parser for the wikipedia:// deeplink scheme only checked that the authority ended with the base domain, so an attacker-controlled URL like evil-wikipedia.org passed validation. Combined with a similar flaw in the cookie manager that checked domain.endsWith(domainSpec), attackers could load a spoofed page inside the app's WebView and steal long-lived Wikimedia session cookies, giving full account takeover. Mobile developers reviewing deeplink and WebView cookie handling can follow findings like this on daily.dev."}},{"@type":"Question","name":"What are the limitations of using LLMs to find and assess Android security vulnerabilities?","acceptedAnswer":{"@type":"Answer","text":"LLMs are effective at finding logic vulnerabilities and understanding API behavior across languages, but they struggle at estimating severity accurately, often reporting low-impact bugs even when told not to and missing mitigating factors like internal storage overwriting attacker-controlled external storage data in path traversal cases. Explicit prompting for proof-of-concept creation and human researcher review are needed to filter false positives. Teams weighing AI-assisted security tooling against manual review can follow this tradeoff discussion on daily.dev."}}]}
```

