A targeted workflow reported 24 Android vulnerabilities

GitHub Security Lab says AI-assisted taskflows helped it find and report 24 vulnerabilities in Android apps. Rather than asking one broad prompt to audit an app, the workflow guides a model through focused stages.

One disclosed OsmAnd issue involved an exported Android activity that could accept settings from another app. GitHub says the path could alter map settings and expose location-related data. Source: https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/

The workflow narrows the search; a researcher verifies impact

The taskflows identify app entry points, then ask the model to consider vulnerability classes relevant to those components. GitHub describes repeated runs: strict prompts catch expected bug patterns while broader prompts can surface less obvious connections.

This is a useful pattern for code agents, but it does not make every generated finding a confirmed bug. GitHub says the model sometimes misjudges severity, misses mitigating details or returns false positives. A researcher still has to reproduce an issue and assess impact.

The open workflow has real costs

GitHub says developers need a Copilot license and premium model requests to run the taskflows in a Codespace. A medium-sized repository can take an hour or two and involve many tool calls.

The report also details a separate Wikipedia Android deeplink issue. The examples are disclosed cases, not proof AI autonomously found every weakness or that the 24 findings had equal severity. Prompts and scripts are inspectable; validation and disclosure remain human work.

Explore the original source ↗

Source published September 28, 2026. Coverage is based on the maker’s announcement and demonstration.