← Back to the wire

How we found 24 Android vulnerabilities using our open source AI security agent

AchievementProductSep 28, 2026

Using the GitHub Security Lab Taskflow Agent, a GitHub security researcher has reported 24 vulnerabilities in Android applications, including a flaw in the OsmAnd navigation app that lets malicious apps track device location via exported MapActivity intent extras. The open-source taskflows guide LLMs through incremental auditing steps and require a GitHub Copilot license, consuming premium model requests. Combined strict and broad prompts across multiple runs help the AI find both obvious and complex vulnerabilities.

Receipt № 21291 source · awaiting confirmation ◐

Evidence

1source· awaiting independent confirmation

No score is assigned. Sources and their independence are shown in the citation chain below.

Citation chain · 1 source

GitHubCompanyGitHub CopilotModelGitHub Security Lab Taskflow AgentModel
Canonical: https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/