Vibeleaderboard
← All Intel
Intel / blog

How we found 24 Android vulnerabilities using our open source AI security agent

Source
Kevin Stubbings
Author
Kevin Stubbings
Date
Key takeaways · AI-distilled
  • The Android taskflows first split entry points into mobile and non-mobile, then walk the model through a fixed checklist of vulnerability classes per entry point, such as confused deputy or insecure broadcasts for intents, mixing strict and open-ended prompts across runs.
  • In OsmAnd (10M+ Android downloads), an exported MapActivity trusted intent extras meant for an AIDL service, letting any app with no permissions silently import settings, point map tiles at an attacker server, and leak visited tile coordinates and route endpoints.
  • In the Wikipedia Android app, an endsWith hostname check on wikipedia:// deeplinks, repeated in the cookie manager, let a domain like evil-wikipedia.org load in the WebView and receive long-lived Wikimedia session cookies, enabling account takeover.
  • The author says the over-reported low-severity and near-impossible bugs and misjudged severity when mitigating factors applied, so every finding needed review by a mobile security researcher. Asking it to build a proof of concept helped surface false positives.
  • The team found the model understood security-relevant API behavior well even without the language's source code, and proofs of concept it generated from a vulnerability report usually needed little modification.
Terms in this piece · Glossary
  • AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
  • LLM — A large language model — the neural network behind tools like Claude and ChatGPT, trained on huge amounts of text to predict what comes next.
Why it matters

Splitting an audit into incremental taskflow steps helps an LLM find complex vulnerabilities it would miss in one pass. The open-source taskflows can be run on your own repo, though they consume many premium requests.

Read the source github.blog
Recommended reads
Comments

Checking sign-in…

Loading comments…