# GitHub researcher reports 24 Android flaws found with AI audit workflows

_Published Monday, September 28, 2026 at 4:08 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![GitHub researcher reports 24 Android flaws found with AI audit workflows — Primary](https://github.blog/wp-content/uploads/2026/01/generic-security-invertocat-blocks-copilot.png?fit=1920%2C1080)

A GitHub security researcher says AI audit workflows helped find and report 24 vulnerabilities in Android apps. In disclosed examples, a flaw in OsmAnd could let another app silently change map settings to expose location and route data. Two flaws in Wikipedia's Android app could be combined to send account cookies to an attacker-controlled page.

The open-source workflows guide a model through app entry points and likely vulnerability classes. Running them requires a GitHub Copilot license and can consume many premium model requests. The researcher says security specialists still need to review findings because the model can misjudge severity and overlook mitigating factors.

## Sources

- [The GitHub Blog](https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/)

---
Canonical: https://techandbusiness.org/newswire/BIcACFYu0lQiHh-Sdw2Mz1
Published: 2026-09-28T20:08:00.471Z
Story chronology: 2026-09-28T19:00:00.000Z
Retrieved: 2026-09-28T22:09:07.235Z
Publisher: Tech & Business (techandbusiness.org)
