Security1 publisher2 min readPublished Updated
GitHub Security Lab's AI taskflows turned up 24 flaws in Android apps including OsmAnd and Wikipedia
GitHub Security Lab's Kevin Stubbings used AI audit workflows to find and report 24 Android app flaws, among them bugs in OsmAnd and Wikipedia. The workflows are free to run on any repository, so the same audit is open to defenders and attackers alike.
The Watch · Security desk

What happened
- OsmAnd, with over 10 million Play Store downloads, exposed a MapActivity that accepted internal-only intent extras, so any app with no permissions could silently swap its map tile server.
- Wikipedia's Android app checked deeplink hostnames with endsWith(), so a wikipedia:// link could load a lookalike such as evil-wikipedia.org inside the app's trusted WebView.
- Stubbings added mobile-only steps that split app entry points from web or desktop ones and push the model toward intent bugs such as confused deputies and insecure broadcasts.
- Stubbings said the model kept flagging low-severity issues even after it was told not to.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any Android app with an exported activity that trusts internal extras, or a suffix-matched host feeding a WebView, is open to the same zero-permission or one-tap attacks.
- cost Each run draws on a GitHub Copilot license and premium model requests that pile up even on one medium-sized codebase, so scanning a whole app portfolio has to be budgeted.
- constraint The model's severity calls cannot be used to sort the queue, so every finding waits on a reviewer who knows mobile apps before it is filed or disclosed.
A suffix check for wikipedia.org passes evil-wikipedia.org, because the lookalike ends in the same characters [2]. The Wikipedia chain then needs a second bug. A flawed check in the app's cookie manager let the WebView pull the victim's long-lived session cookies [6]. The token that comes out is valid across every Wikimedia project, and getting it takes one tapped link [6].
OsmAnd's bug asks more of the attacker. A hostile app has to be on the same phone, though it needs no permissions [3]. Once the tile source points at the attacker's server, the attacker can log the exact coordinates of every tile the victim loads and reconstruct their routes, with nothing visible to the user [4]. I'd rate the Wikipedia chain the easier of the two to exploit. A link can be sent to anyone, while the OsmAnd attack needs an install first [3][6].
According to Stubbings, the model was better at finding bugs than at judging how bad they were [13]. It also got real-world impact wrong where a mitigating factor cancelled what looked like a working exploit. The example given is internal storage silently overriding attacker-controlled external storage [9].
Help Net Security's account details two of the 24 findings, leaving 22 undescribed [1]. It does not give CVE numbers, fixed versions for OsmAnd or Wikipedia, or any report of the taskflows being run outside GitHub Security Lab [2].
The case for expecting attackers to run the same audits rests on access to the tooling. Stubbings built the taskflows on the lab's open source Taskflow Agent [1].
What to watch
- Advisories or release notes from OsmAnd and Wikimedia naming fixed versions for the MapActivity and deeplink-plus-cookie flaws.
- GitHub Security Lab publishing details of the other 22 findings.
- Any report of these taskflows, or similar agent workflows, turning up Android bugs outside a coordinated disclosure.