HeadlinesBriefing favicon HeadlinesBriefing.com

Encontramos 24 vulnerabilidades do Android com agente de IA

Hacker News •
×

Our team developed the GitHub Security Lab Taskflow Agent to automate and share effective AI security workflows. Using custom taskflows, we audited Android applications and discovered 24 vulnerabilities, including high-impact issues like confused deputy and insecure broadcasts. These taskflows guide LLMs through incremental steps, improving detection of complex bugs that models might otherwise miss. The open-source tool requires a GitHub Copilot license and runs via a codespace. After execution, results appear in an SQLite viewer where vulnerabilities are flagged in the "has_vulnerability" column. We tailored prompts for mobile-specific risks, such as intent-based entry points, to enhance accuracy. Two disclosed vulnerabilities are highlighted: one in OsmAnd (a navigation app with over 10 million downloads) involving malicious APK tracking, and another demonstrating cross-component attacks. The approach balances strict checks with creative analysis, ensuring both common and obscure flaws are caught. Researchers can replicate the process on their own repositories using the provided scripts.

Key entities include GitHub, GitHub Copilot, OsmAnd, OpenStreetMap, and the seclab-taskflows repository. The method underscores how structured AI prompts can scale security auditing across diverse codebases.