The GitHub Security Lab has introduced the Taskflow Agent, an open-source tool that uses artificial intelligence to automate the identification of vulnerabilities in Android applications. This tool allows security researchers to create custom taskflow prompts, leading to the discovery of over 20 vulnerabilities. To use the taskflows, a GitHub Copilot license is required, and users can run scripts to audit their projects, with results displayed in an SQLite viewer. Two specific vulnerabilities identified include:
1. OsmAnd app allows malicious applications to track user locations due to improper handling of intent extras in its exported activity.
2. The Wikipedia app has a logic flaw that enables attackers to redirect users to malicious sites via a deeplink mechanism, potentially leading to account takeovers.
The GitHub Security Lab has reported a total of 24 vulnerabilities in Android applications, highlighting the effectiveness of AI in security research.