GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking Flaw and Wikipedia Account Takeover

GitHub Security Lab AI Agent Uncovers 24 Android App (TL-2026-2744) is a medium-severity software vulnerability, first published 2026-09-28. It has no confirmed attribution, affects OsmAnd OsmAnd (Android), maps to 9 MITRE ATT&CK techniques (T1204.001, T1409, T1430), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-2744

Threat ID
TL-2026-2744
Severity
MEDIUM
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-28
Last reviewed
2026-09-28
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer, technology
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in GitHub Security Lab AI Agent Uncovers 24 Android App

Malware and tooling: GitHub Codespaces, GitHub Copilot, GitHub Security Lab Taskflow Agent

GitHub Security Lab used its open-source Taskflow Agent, an LLM-driven structured security-auditing framework, to discover 24 vulnerabilities across Android applications. Two are detailed: an OsmAnd (10M+ downloads) flaw where an exported MapActivity handling deeplinks and settings files lets a malicious app harvest a victim's precise location via unvalidated intent extras, and a logic bug in the Wikipedia Android app's deeplink handler enabling phishing and session hijacking via cookie theft across Wikimedia projects.

How GitHub Security Lab AI Agent Uncovers 24 Android App works

GitHub Security Lab publicly detailed the results of running its open-source Taskflow Agent — a YAML-driven, LLM-backed structured security-auditing framework built on the OpenAI Agents SDK — against a set of Android applications, surfacing 24 vulnerabilities. The agent is invoked via `./scripts/audit/run_mobile.sh myorg/myrepo` inside GitHub Codespaces, requires a GitHub Copilot license for its premium model requests, and typically completes a medium-sized repository audit in 1-2 hours. Two Android-specific taskflows drove the analysis: `gather_mobile_entry_point_info.yaml`, which separates mobile from non-mobile entry points, and `classify_application_local.yaml`, which focuses the model on mobile-specific vulnerability classes such as intent confusion and insecure broadcasts.

The post details two findings with clear real-world impact. First, OsmAnd (10M+ downloads) exports an Activity, `MapActivity`, that handles both deeplinks and settings-file imports. Its `handleOsmAndSettingsImport()` handler accepts intent extras (`settings_version`, `silent_import`, `replace`, `export_type_list_key`) that were only ever meant to arrive from a trusted in-process AIDL service — but because the Activity is exported, any application installed on the device can send it an Intent carrying arbitrary extras. A malicious app can import a crafted malicious tile-source configuration pointing at an attacker-controlled domain (`{ATTACKER_DOMAIN}/tiles/{z}/{x}/{y}.png`); every subsequent map-tile request OsmAnd makes then leaks the tile coordinates (i.e., the victim's precise latitude/longitude), plus route origins, destinations, and timestamps, to the attacker's server — silently, with no user-visible indication of compromise.

Second, the Wikipedia Android app contains two chained logic bugs. Its deeplink handler validates the authority of a `wikipedia://` URI only by checking `endsWith(WikiSite.BASE_DOMAIN)` rather than exact-matching a trusted domain, so a deeplink such as `wikipedia://evil-wikipedia.org` passes validation and is rewritten to a standard `https://evil-wikipedia.org` URI that the app then opens. Separately, `SharedPreferenceCookieManager.kt` validates cookie domains using the same overly permissive `.endsWith()` comparison. Chained together, a victim who taps a single malicious deeplink has the Wikipedia app auto-open attacker-controlled content and leak cookies to it — yielding the victim's username, long-lived tokens, and session tokens valid across every Wikimedia project (all Wikipedias, Commons, Wikidata, Meta, and more), enabling account takeover.

GitHub Security Lab states the two detailed findings were 'already disclosed,' but the post supplies no CVE identifiers, CVSS scores, patch status, or remediation timeline for either issue, and gives only high-level categories (path traversal, cross-app scripting in WebView implementations, exposed JavaScript bridges) for the remaining 22 undetailed vulnerabilities, pointing readers to GitHub Security Lab's advisories page for further detail. The post also documents the Taskflow Agent's current limitations: LLMs struggle to estimate severity accurately, produce false positives requiring human security-researcher validation, and can misjudge complex mitigating factors (e.g., internal vs. external storage data-priority hierarchies) without explicit proof-of-concept prompting — while showing strong knowledge of platform API behavior across languages without needing source-code access.

MITRE ATT&CK techniques used in TL-2026-2744

Execution

T1204.001 Malicious Link; T1559 Inter-Process Communication

Collection

T1409 Stored Application Data; T1430 Location Tracking

Discovery

T1430 Location Tracking

Command and Control

T1437.001 Web Protocols

Defense Evasion

T1516 Input Injection

Credential Access

T1539 Steal Web Session Cookie; T1635.001 URI Hijacking

Initial Access

T1660 Phishing

Affected products and versions in GitHub Security Lab AI Agent Uncovers 24 Android App

  • OsmAnd — OsmAnd (Android)
    Vulnerable versions: current app version at time of research (10M+ downloads); exact version range not disclosed
  • Wikimedia Foundation — Wikipedia (Android)
    Vulnerable versions: current app version at time of research; exact version range not disclosed

Remediation for GitHub Security Lab AI Agent Uncovers 24 Android App

Immediate actions

  • Remove or restrict android:exported="true" on Activities/components that process sensitive intent extras (e.g., settings-import handlers); require an explicit permission or verify the calling package/signature before acting on extras from an untrusted caller.
  • Replace suffix-based domain/authority checks (endsWith()) with exact string-equality or a validated allow-list when checking deeplink authorities and cookie domains in Android apps.
  • Treat any tile/asset-loading configuration importable via Intent as untrusted input; validate or pin the host before issuing outbound requests.
  • Monitor the OsmAnd and Wikipedia Android app store listings for security-patch updates and apply them promptly once released; no patch was confirmed at time of publication.

Workarounds

  • No public vendor patch confirmed at time of publication for either the OsmAnd or Wikipedia Android findings; avoid installing untrusted third-party Android apps alongside OsmAnd to reduce local intent-injection exposure.
  • Avoid tapping wikipedia:// deeplinks received from untrusted sources (SMS, email, third-party apps, QR codes) until the Wikipedia Android app is confirmed patched.

Longer-term hardening

  • Integrate AI-assisted structured security-auditing tools such as the GitHub Security Lab Taskflow Agent into the mobile app SDLC to systematically catch exported-component and intent-handling flaws before release.
  • Add automated CI linting for exported Android components that accept intent extras without caller verification (e.g., Android Lint exported-component checks, MobSF static analysis).
  • Adopt strict origin/domain equality checks across all URI-scheme handlers and cookie-domain validation logic, and add regression tests specifically for suffix-matching bypass patterns.
  • Independently review LLM-generated vulnerability severity/impact assessments from agentic security tooling with a human researcher before acting on them, per GitHub Security Lab's own documented limitation.

Weaknesses (CWE) in GitHub Security Lab AI Agent Uncovers 24 Android App

CWE-940, CWE-925, CWE-183

Timeline of GitHub Security Lab AI Agent Uncovers 24 Android App

  • Post references 22 additional, undetailed Android vulnerabilities (categorized only as path traversal, cross-app scripting in WebView implementations, and exposed JavaScript bridges) and directs readers to GitHub Security Lab's advisories page.
  • Blog notes the Taskflow Agent requires a GitHub Copilot license for premium model requests and runs via GitHub Codespaces (./scripts/audit/run_mobile.sh myorg/myrepo), typically completing in 1-2 hours on a medium repository.
  • GitHub Security Lab points readers to its open-sourced Taskflow Agent repositories (seclab-taskflow-agent, seclab-taskflows) so others can run the same taskflows against their own projects.
  • GitHub Security Lab states the two detailed findings were 'already disclosed,' but the post provides no CVE identifiers, CVSS scores, patch status, or remediation timeline for either issue.
  • Wikipedia Android app's chained deeplink-authority-validation and cookie-domain-validation logic bugs, enabling phishing and cross-Wikimedia-project session hijacking, are publicly detailed.
  • OsmAnd's exported MapActivity location-tracking vulnerability (unvalidated settings-import intent extras leaking tile coordinates to an attacker server) is publicly detailed.
  • Blog details the Taskflow Agent's two Android-specific taskflows — gather_mobile_entry_point_info.yaml and classify_application_local.yaml — used to conduct the audits.
  • GitHub Security Lab publishes 'How we found 24 Android vulnerabilities using our open source AI security agent' on the GitHub Blog.

Sources cited for GitHub Security Lab AI Agent Uncovers 24 Android App

More in vulnerability

Detection coverage for TL-2026-2744

As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2744 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats