GitHub Security Lab finds 24 Android vulnerabilities with AI agent
GitHub Security Lab has used its open-source AI security framework, Taskflow Agent, to discover 24 vulnerabilities in Android and related apps. The framework, introduced in January 2026, allows security researchers to break down complex analysis into incremental 'taskflows' and share successful prompts. One vulnerability in the OsmAnd app could have allowed attackers to steal tracking data from Android users, while another in the Wikipedia app could have led to account takeover. Kevin Stubbings of GitHub Security Lab emphasized that while AI can help find complex issues, it still requires human review to assess risk accurately and avoid false positives. The team believes AI-driven security research is currently the best way to protect open-source projects.
- •GitHub Security Lab's Taskflow Agent discovered 24 vulnerabilities in Android.
- •One vulnerability in OsmAnd could allow theft of tracking data.
- •A vulnerability in the Wikipedia Android app could allow account takeover.
