Full Report
A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app. The post How we found 24 Android vulnerabilities using our open source AI security agent appeared first on The GitHub Blog.
Analysis Summary
# Vulnerability: Multiple Android Flaws (Location Tracking & Intent-Based Exploits)
## CVE Details
- **CVE ID**: Not explicitly listed for all 24 findings in the article summary (Refers to [GitHub Security Lab Advisories](https://securitylab.github.com/ai-agents/) for individual IDs).
- **CVSS Score**: Varies (Findings range from "Simple" to "Critical").
- **CWE**:
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-79: Cross-site Scripting (XSS) via WebViews
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
- CWE-912: Managed Software/JavaScript Bridge Vulnerabilities
## Affected Systems
- **Products**: OsmAnd (Navigation App) and various other open-source Android applications.
- **Versions**: Android versions of OsmAnd with >10 million downloads; specific version numbers for all 24 apps are maintained in the GitHub Security Lab advisory database.
- **Configurations**: Applications exporting specific components (Activities, Services, or Broadcast Receivers) or using insecure WebView/JavaScript bridge implementations.
## Vulnerability Description
The vulnerabilities were identified using the **GitHub Security Lab Taskflow Agent**, an AI-powered auditing tool.
- **Information Leakage (OsmAnd)**: The `MapActivity` was exported, allowing unauthorized third-party apps to interact with it. By sending specific Intents, a malicious app could force the application to reveal the device's location.
- **Cross-App Scripting (XAS)**: Vulnerabilities in WebViews where attacker-controlled data could reach a JavaScript bridge, allowing for code execution or data theft within the context of the vulnerable app.
- **Path Traversal**: Improper validation of file paths in app entry points, allowing access to private application data.
- **Confused Deputy**: Vulnerabilities where a privileged app is tricked by a less-privileged app into performing an action (e.g., sending an insecure broadcast).
## Exploitation
- **Status**: PoCs available (generated by the AI agent during the research phase). 24 vulnerabilities reported to maintainers.
- **Complexity**: Low to Medium (depending on the specific entry point).
- **Attack Vector**: Local (Malicious app installed on the same device) or Adjacent.
## Impact
- **Confidentiality**: **High** (Sensitive user location data and private app files can be accessed).
- **Integrity**: **Medium** (Potential for XSS and unauthorized action execution).
- **Availability**: **Low** (Focus of findings was primarily data exposure and execution).
## Remediation
### Patches
- Users of **OsmAnd** and other affected apps should update to the latest versions available on the Google Play Store or F-Droid.
- Maintainers are advised to review pull requests and advisories issued by the GitHub Security Lab.
### Workarounds
- **Developers**: Disable `android:exported="true"` for Activities, Services, and Receivers unless explicitly required for inter-app communication.
- **Developers**: Implement strict validation for incoming Intents and sanitize inputs to WebViews.
## Detection
- **Indicators of Compromise**: Unusually frequent Intent calls between unrelated applications; unauthorized access to location services via proxy apps.
- **Detection Methods**:
- **GitHub Security Lab Taskflow Agent**: Run the open-source agent using the `run_mobile.sh` script against application source code.
- **Static Analysis**: Audit `AndroidManifest.xml` for exported components and `WebView` configurations for `addJavascriptInterface`.
## References
- GitHub Security Lab Advisories: hxxps://securitylab.github[.]com/ai-agents/
- GitHub Taskflow Agent Repository: hxxps://github[.]com/github/seclab-taskflows
- Original Blog Post: hxxps://github[.]blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/