GitHub's open source agent found silent GPS tracking in a 10 million download navigation app and a Wikipedia session theft chain, then admitted its severity scoring is unreliable.
An AI security agent just found 24 real bugs in apps you might have installed.
GitHub's open-source Taskflow Agent, a YAML-configured framework that guides a large language model through structured security audits, reported 24 vulnerabilities in production Android apps on September 28. The list includes a silent GPS-tracking flaw in OsmAnd, a navigation app with more than 10 million Android downloads, and a chain of hostname and cookie-validation flaws in the Wikipedia Android app. After a victim taps a malicious link, that chain could expose account cookies and session tokens on every Wikimedia project. Session tokens are login credentials that stay valid across visits.
The OsmAnd bug sat in a settings-import flow. An exported activity (an Android component any other installed app can trigger) left it open, so any installed app could redirect a route request and read the user's destination. The Wikipedia chain ran through malicious deeplinks, the kind of link that opens a specific page inside an app.
The same run surfaced a limit the team itself flagged. The agent could not reliably judge how bad a bug was because it missed runtime mitigations, including cases where internal app data overrides attacker-controlled external-storage data. The model treats the attacker's input as live. The device does not.
GitHub's report recommends a mobile-security expert review every finding before action. The agent expands the surface area a small team can cover in a single pass. It does not let any one person skip the review.