GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking Flaw and Wikipedia Account Takeover
GitHub Security Lab AI Agent Uncovers 24 Android App (TL-2026-2744) is a medium-severity software vulnerability, first published 2026-09-28. It has no confirmed attribution, affects OsmAnd OsmAnd (Android), maps to 9 MITRE ATT&CK techniques (T1204.001, T1409, T1430), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-2744
- Threat ID
- TL-2026-2744
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- consumer, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in GitHub Security Lab AI Agent Uncovers 24 Android App
Malware and tooling: GitHub Codespaces, GitHub Copilot, GitHub Security Lab Taskflow Agent
GitHub Security Lab used its open-source Taskflow Agent, an LLM-driven structured security-auditing framework, to discover 24 vulnerabilities across Android applications. Two are detailed: an OsmAnd (10M+ downloads) flaw where an exported MapActivity handling deeplinks and settings files lets a malicious app harvest a victim's precise location via unvalidated intent extras, and a logic bug in the Wikipedia Android app's deeplink handler enabling phishing and session hijacking via cookie theft across Wikimedia projects.
How GitHub Security Lab AI Agent Uncovers 24 Android App works
GitHub Security Lab publicly detailed the results of running its open-source Taskflow Agent — a YAML-driven, LLM-backed structured security-auditing framework built on the OpenAI Agents SDK — against a set of Android applications, surfacing 24 vulnerabilities. The agent is invoked via `./scripts/audit/run_mobile.sh myorg/myrepo` inside GitHub Codespaces, requires a GitHub Copilot license for its premium model requests, and typically completes a medium-sized repository audit in 1-2 hours. Two Android-specific taskflows drove the analysis: `gather_mobile_entry_point_info.yaml`, which separates mobile from non-mobile entry points, and `classify_application_local.yaml`, which focuses the model on mobile-specific vulnerability classes such as intent confusion and insecure broadcasts.
The post details two findings with clear real-world impact. First, OsmAnd (10M+ downloads) exports an Activity, `MapActivity`, that handles both deeplinks and settings-file imports. Its `handleOsmAndSettingsImport()` handler accepts intent extras (`settings_version`, `silent_import`, `replace`, `export_type_list_key`) that were only ever meant to arrive from a trusted in-process AIDL service — but because the Activity is exported, any application installed on the device can send it an Intent carrying arbitrary extras. A malicious app can import a crafted malicious tile-source configuration pointing at an attacker-controlled domain (`{ATTACKER_DOMAIN}/tiles/{z}/{x}/{y}.png`); every subsequent map-tile request OsmAnd makes then leaks the tile coordinates (i.e., the victim's precise latitude/longitude), plus route origins, destinations, and timestamps, to the attacker's server — silently, with no user-visible indication of compromise.
Second, the Wikipedia Android app contains two chained logic bugs. Its deeplink handler validates the authority of a `wikipedia://` URI only by checking `endsWith(WikiSite.BASE_DOMAIN)` rather than exact-matching a trusted domain, so a deeplink such as `wikipedia://evil-wikipedia.org` passes validation and is rewritten to a standard `https://evil-wikipedia.org` URI that the app then opens. Separately, `SharedPreferenceCookieManager.kt` validates cookie domains using the same overly permissive `.endsWith()` comparison. Chained together, a victim who taps a single malicious deeplink has the Wikipedia app auto-open attacker-controlled content and leak cookies to it — yielding the victim's username, long-lived tokens, and session tokens valid across every Wikimedia project (all Wikipedias, Commons, Wikidata, Meta, and more), enabling account takeover.
GitHub Security Lab states the two detailed findings were 'already disclosed,' but the post supplies no CVE identifiers, CVSS scores, patch status, or remediation timeline for either issue, and gives only high-level categories (path traversal, cross-app scripting in WebView implementations, exposed JavaScript bridges) for the remaining 22 undetailed vulnerabilities, pointing readers to GitHub Security Lab's advisories page for further detail. The post also documents the Taskflow Agent's current limitations: LLMs struggle to estimate severity accurately, produce false positives requiring human security-researcher validation, and can misjudge complex mitigating factors (e.g., internal vs. external storage data-priority hierarchies) without explicit proof-of-concept prompting — while showing strong knowledge of platform API behavior across languages without needing source-code access.
MITRE ATT&CK techniques used in TL-2026-2744
Execution
T1204.001 Malicious Link; T1559 Inter-Process Communication
Collection
T1409 Stored Application Data; T1430 Location Tracking
Discovery
Command and Control
Defense Evasion
Credential Access
T1539 Steal Web Session Cookie; T1635.001 URI Hijacking
Initial Access
Affected products and versions in GitHub Security Lab AI Agent Uncovers 24 Android App
- OsmAnd — OsmAnd (Android)
Vulnerable versions: current app version at time of research (10M+ downloads); exact version range not disclosed - Wikimedia Foundation — Wikipedia (Android)
Vulnerable versions: current app version at time of research; exact version range not disclosed
Remediation for GitHub Security Lab AI Agent Uncovers 24 Android App
Immediate actions
- Remove or restrict android:exported="true" on Activities/components that process sensitive intent extras (e.g., settings-import handlers); require an explicit permission or verify the calling package/signature before acting on extras from an untrusted caller.
- Replace suffix-based domain/authority checks (endsWith()) with exact string-equality or a validated allow-list when checking deeplink authorities and cookie domains in Android apps.
- Treat any tile/asset-loading configuration importable via Intent as untrusted input; validate or pin the host before issuing outbound requests.
- Monitor the OsmAnd and Wikipedia Android app store listings for security-patch updates and apply them promptly once released; no patch was confirmed at time of publication.
Workarounds
- No public vendor patch confirmed at time of publication for either the OsmAnd or Wikipedia Android findings; avoid installing untrusted third-party Android apps alongside OsmAnd to reduce local intent-injection exposure.
- Avoid tapping wikipedia:// deeplinks received from untrusted sources (SMS, email, third-party apps, QR codes) until the Wikipedia Android app is confirmed patched.
Longer-term hardening
- Integrate AI-assisted structured security-auditing tools such as the GitHub Security Lab Taskflow Agent into the mobile app SDLC to systematically catch exported-component and intent-handling flaws before release.
- Add automated CI linting for exported Android components that accept intent extras without caller verification (e.g., Android Lint exported-component checks, MobSF static analysis).
- Adopt strict origin/domain equality checks across all URI-scheme handlers and cookie-domain validation logic, and add regression tests specifically for suffix-matching bypass patterns.
- Independently review LLM-generated vulnerability severity/impact assessments from agentic security tooling with a human researcher before acting on them, per GitHub Security Lab's own documented limitation.
Weaknesses (CWE) in GitHub Security Lab AI Agent Uncovers 24 Android App
CWE-940, CWE-925, CWE-183
Timeline of GitHub Security Lab AI Agent Uncovers 24 Android App
- Post references 22 additional, undetailed Android vulnerabilities (categorized only as path traversal, cross-app scripting in WebView implementations, and exposed JavaScript bridges) and directs readers to GitHub Security Lab's advisories page.
- Blog notes the Taskflow Agent requires a GitHub Copilot license for premium model requests and runs via GitHub Codespaces (./scripts/audit/run_mobile.sh myorg/myrepo), typically completing in 1-2 hours on a medium repository.
- GitHub Security Lab points readers to its open-sourced Taskflow Agent repositories (seclab-taskflow-agent, seclab-taskflows) so others can run the same taskflows against their own projects.
- GitHub Security Lab states the two detailed findings were 'already disclosed,' but the post provides no CVE identifiers, CVSS scores, patch status, or remediation timeline for either issue.
- Wikipedia Android app's chained deeplink-authority-validation and cookie-domain-validation logic bugs, enabling phishing and cross-Wikimedia-project session hijacking, are publicly detailed.
- OsmAnd's exported MapActivity location-tracking vulnerability (unvalidated settings-import intent extras leaking tile coordinates to an attacker server) is publicly detailed.
- Blog details the Taskflow Agent's two Android-specific taskflows — gather_mobile_entry_point_info.yaml and classify_application_local.yaml — used to conduct the audits.
- GitHub Security Lab publishes 'How we found 24 Android vulnerabilities using our open source AI security agent' on the GitHub Blog.
Sources cited for GitHub Security Lab AI Agent Uncovers 24 Android App
- How we found 24 Android vulnerabilities using our open source AI security agent
- GitHubSecurityLab/seclab-taskflow-agent
- GitHubSecurityLab/seclab-taskflows — example taskflows for the Taskflow Agent
- seclab-taskflow-agent README (v0.0.9)
- AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent
- AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
- Community-powered security with AI: an open source framework for security research
- OsmAnd MapActivity.java (source)
- GitHub announcement: Taskflow Agent open-sourced for Auth Bypasses, IDORs, Token Leaks
- AI Agents | GitHub Security Lab — All advisories discovered with AI agents
More in vulnerability
- CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write
- CVE-2026-42542: TDengine unauthenticated integer underflow lets a single RPC packet crash taosd
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)
Detection coverage for TL-2026-2744
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2744 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.