GitHub安全实验室的研究团队利用开源AI安全代理工具创建了Android应用审计工作流,成功识别出24个Android应用中的安全漏洞1。该团队通过自定义提示词指导AI模型逐步发掘复杂漏洞,其中包括位置追踪和账户接管等严重安全问题1。
在具体发现中,OsmAnd应用存在漏洞允许恶意应用通过导出的MapActivity拦截intent extras,进而通过修改瓦片URL追踪用户位置和路线信息1。Wikipedia应用则因hostname解析逻辑漏洞,使得深层链接可加载非维基百科URL,结合Cookie检查绕过可能导致账户接管1。
该任务流以开源项目形式发布,需要GitHub Copilot许可证支持,在中等规模代码库上运行耗时1至2小时1。研究团队指出,AI在漏洞发现方面表现良好,但在评估漏洞严重程度和理解复杂应用行为方面存在局限1。
GitHub Security Lab's research team deployed an open source AI security agent to audit Android applications, successfully identifying 24 vulnerabilities across the platform 1. The team utilized custom prompts to guide the AI model through systematic analysis, enabling the discovery of complex security flaws.
Among the critical findings was a location-tracking vulnerability in OsmAnd that allows malicious applications to intercept intent extras through an exported MapActivity, then modify tile URLs to track user location and route information 1. The Wikipedia application contained a separate account takeover vulnerability stemming from hostname resolution logic flaws, where deeplinks could load non-Wikipedia URLs and, when combined with bypassed Cookie checks, could compromise user accounts 1.
The audit workflow is available as an open source project requiring a GitHub Copilot license, with processing time for mid-sized codebases ranging from one to two hours 1. While the AI demonstrated strong capability in vulnerability discovery, the research revealed limitations in assessing severity levels and understanding complex application behaviors 1.
评论
还没有评论,欢迎留下第一条。