GitHub Security Lab said on September 28, 2026 that a researcher used its open source Taskflow Agent, an LLM-driven auditing tool, to find and report 24 vulnerabilities in Android applications, including flaws in the OsmAnd navigation app and the Wikipedia Android app.
How the taskflows work
GitHub said it built the GitHub Security Lab Taskflow Agent so security researchers can automate, package and share the AI prompts and workflows they find effective. According to the post, custom taskflow prompts let researchers guide models by splitting research into incremental steps, helping the LLM find complex vulnerabilities faster or ones it would have missed entirely.
For Android work, the author said they added a taskflow called gather_mobile_entry_point_info.yaml that separates entry points into mobile and non-mobile ones, so the model understands the correct attack surface in repositories containing several application types. They also edited classify_application_local.yaml to list popular vulnerability classes the LLM must consider for each entry point and component, such as confused deputy or insecure broadcasts for intent-based entry points.
GitHub said the taskflows are open source and can be run from a codespace in the seclab-taskflows repository, but that a GitHub Copilot license is required and the prompts use premium model requests.
OsmAnd location tracking
GitHub described OsmAnd as a third-party navigation app using OpenStreetMap as its main data source, with the Android version having over 10 million downloads. Three vulnerabilities were discovered; the post details one that it said allows malicious apps to track a device's location.
According to the write-up, OsmAnd exports an activity called MapActivity that handles settings files and deeplinks and accepts intent extras including settings_version, silent_import, replace and export_type_list_key. The post said those extras were only expected to come from an AIDL service and should have been passed through an in-process channel, because any app can attach arbitrary extras to an intent sent to an exported activity and Android provides no mechanism to restrict which extras an external caller can set.
GitHub said an attacker app can therefore import settings silently, replace map tiles with an attacker-hosted tile URL, and recover the x and y coordinates of every tile the user loads, as well as the origin and destination of every route — all without a change noticeable to the user, and from an app with no permissions.
Wikipedia app deeplink chain
The second example concerns the Wikipedia Android app, which registers a hook for the wikipedia:// deeplink. GitHub said a logic bug in the hostname parser — an endsWith check against the base domain — allows loading non-Wikipedia URLs, so a domain such as evil-wikipedia.org passes the check.
The post said the same pattern appears twice, including in cookie handling, allowing an attacker to run arbitrary JavaScript in the app's WebView and leak long-lived cookies. Chained together, GitHub said the issues yield an account takeover giving the attacker the victim's username, long-lived token and a session token valid across every Wikimedia project.
Limits of the LLM approach
GitHub said LLMs are good at finding vulnerabilities but struggle at estimating severity, often reporting low-severity issues even when told not to, and missing mitigating factors. It said each finding should be reviewed by a security researcher with knowledge of mobile applications.
The post said complex behaviors, such as internal storage taking priority over attacker-writable external storage, lead to false positives, and that current fixes include giving the LLM a debugger to run a proof of concept or having a researcher prompt for those specific issues. It added that the team was surprised how well the model understood security-relevant API behavior across languages.
What to do
- Open the seclab-taskflows repository and start a codespace, then wait a few minutes for it to initialize.
- In the codespace terminal, run ./scripts/audit/run_mobile.sh myorg/myrepo; GitHub says it may take an hour or two on a medium-sized repository.
- When the run finishes, open the audit_results table in the SQLite viewer and look for rows with a checkmark in the has_vulnerability column.
- Budget for cost and capacity: a GitHub Copilot license is required and the runs can make many tool calls that consume a large amount of tokens.
- Have a security researcher with mobile application knowledge review every finding, since GitHub says the LLM misjudges severity and produces false positives.
- Prompt the model to create a proof of concept, or give it a debugger, to check whether mitigating factors reduce or eliminate a reported issue.
Key facts and where they come from
- GitHub Security Lab reported 24 Android vulnerabilities found with its Taskflow Agent.
At the time of writing this blog, we found 24 Android vulnerabilities in mobile applications.
- The OsmAnd Android app has more than 10 million downloads, per GitHub.
we will look at the Android version, which has over 10 million downloads
- OsmAnd's exported MapActivity accepts attacker-settable intent extras.
any app can put arbitrary extras on any intent to any exported activity. Android provides no mechanism to restrict which extras an external caller can set.
- The OsmAnd issue lets an unprivileged app exfiltrate location data.
This allows any app, even one with no permissions, to overwrite the settings of OsmAnd and send back private location data to their server.
- A hostname parser bug in the Wikipedia Android app allows loading non-Wikipedia URLs.
a logic bug in the hostname parser allows us to load non-Wikipedia URLs
- Chaining the Wikipedia app issues yields account takeover across Wikimedia projects.
session token valid across every Wikimedia project (all Wikipedias, Commons, Wikidata, Meta, etc.)
- GitHub says LLM findings need human review because severity is often misjudged.
Because of this, each finding should be reviewed by a security researcher with knowledge of mobile applications.
- Running the taskflows requires a GitHub Copilot license and consumes premium model requests.
A GitHub Copilot license is required, and the prompts will use premium model requests.
