GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws

GitHub Security Lab has revealed that its open-source AI security agent has successfully identified 24 vulnerabilities within various Android applications. Among these findings are critical flaws that could potentially enable covert location tracking in the OsmAnd navigation app and facilitate account takeover attacks against the Wikipedia app for Android.

The research underscores the effectiveness of targeted AI workflows in assisting researchers to uncover intricate mobile logic flaws, while still emphasizing the necessity for human validation in the process.

Utilizing the GitHub Security Lab Taskflow Agent, an open-source framework crafted to automate and share AI-assisted security research workflows, the researchers approached the task with precision. Instead of employing a broad prompt to scan an entire repository, they developed Android-specific taskflows that segmented audits into manageable stages.

  • One taskflow focuses on identifying mobile entry points, including exported activities, services, broadcast receivers, and deep links.
  • Another taskflow evaluates each entry point against Android-centric vulnerability classes, such as insecure intents, confused deputy issues, unsafe broadcasts, cross-app scripting, and WebView risks.

This structured approach enables the AI to comprehend the relevant attack surface within repositories that may encompass mobile, web, and desktop code.

GitHub AI Finds 24 Android Vulnerabilities

Among the most critical vulnerabilities discovered was one affecting OsmAnd, an Android navigation application boasting over 10 million downloads. Researchers identified that the app’s exported MapActivity accepted security-sensitive intent extras while importing settings.

Given that exported Android activities can receive intents from other applications, a malicious app could potentially supply attacker-controlled values such as silentimport, replace, and exporttypelistkey.

This vulnerability allowed an unprivileged malicious application to silently import and replace settings in OsmAnd without notifying the user. An attacker could manipulate the application’s map-tile source, redirecting map requests to an attacker-controlled server. By logging tile coordinates, the attacker could deduce a victim’s location and movements, while the user continued to use the application without any indication of compromise.

In addition, GitHub detailed an account takeover chain involving the Wikipedia Android application. The app registers a wikipedia:// deep link handler to open content within its WebView. However, the hostname validation utilized an endsWith() check rather than validating the exact trusted domain.

This flaw permitted a malicious domain, such as evil-wikipedia.org, to pass the suffix check since its name concludes with wikipedia.org. An attacker could craft a malicious webpage containing a deceptive deep link and entice a victim to open it.

Consequently, the Wikipedia app could load attacker-controlled content within its WebView, potentially misleading the victim into believing they were viewing a legitimate Wikipedia page. A second domain-suffix validation issue within the application’s cookie-handling code exacerbated the situation. This flawed check could lead the WebView to provide Wikimedia cookies to the attacker-controlled page.

Researchers indicated that the compromised data could include a username, long-lived authentication token, and session token valid across Wikimedia projects, encompassing Wikipedia, Wikimedia Commons, Wikidata, and Meta. By chaining these two vulnerabilities, an account takeover could occur simply by a victim clicking a single malicious link.

GitHub has cautioned that findings generated by AI should not be accepted without thorough expert review. While large language models can effectively identify code patterns and pertinent APIs, they may also misjudge severity, overlook mitigating behaviors, or produce false positives.

To enhance triage, researchers found that requiring the model to construct a proof of concept can be beneficial, although human testing remains indispensable. The Taskflow Agent and Android audit workflows are publicly accessible.

GitHub has noted that users will need a GitHub Copilot license, and audits can be resource-intensive, consuming a significant number of premium-model requests. Medium-sized repositories may require one to two hours for completion, necessitating numerous tool calls. The results of these audits are stored in an SQLite audit_results table for further researcher review.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

AppWizard