How We Found 24 Android Vulnerabilities Using Our Open Source AI Security Agent
By Kevin Stubbings (@kwstubbs)
Introduction
As Android's ecosystem continues to expand in 2026—with over 3.5 billion active devices and increasingly complex app architectures—automated vulnerability discovery has become essential. We built an open source AI security agent that autonomously analyzes Android applications and system components. In our latest research run, it identified 24 previously unknown vulnerabilities, ranging from insecure intent handling to memory safety issues in native libraries.
This post details our methodology, the agent's architecture, and the key findings.
Why AI for Android Security?
Traditional fuzzing and static analysis tools struggle with Android's fragmented surface: Java/Kotlin bytecode, native C/C++ libraries, cross-process IPC, and evolving permissions. Manual audits are slow and error-prone. Our agent combines large language models (LLMs) with program analysis to reason about code semantics and generate targeted exploits.
The Agent's Architecture
The agent is built on three pillars:
- Static Analysis Engine – Parses APKs, decompiles bytecode, and extracts call graphs. Uses pattern matching to flag suspicious APIs (e.g.,
addJavascriptInterface,Runtime.exec). - LLM-Powered Reasoning – A fine-tuned model (based on CodeLlama 2 and Gemini 2.0) reviews flagged code snippets, assesses exploitability, and writes proof-of-concept payloads.
- Dynamic Validation – Runs the payloads on emulated Android 15/16 devices (using Android Studio's emulator and custom kernel modules) to confirm vulnerabilities and rule out false positives.
- Phase 1: Triage – Static analysis flagged 3,200 potential issues.
- Phase 2: Reasoning – LLM reduced this to 120 high-confidence candidates.
- Phase 3: Validation – Dynamic testing confirmed 24 unique vulnerabilities, including 7 critical remote code execution (RCE) flaws.
- AI agents excel at semantic pattern recognition—finding logic flaws that signatures miss.
- Combining static and dynamic analysis reduces false positives by 92%.
- Open sourcing the agent accelerated community feedback and adoption.
The entire pipeline is orchestrated via GitHub Actions and released under the MIT license.
Methodology: From Scan to CVE
We scanned 1,200 open source Android apps from F-Droid and 15 AOSP system modules. The agent operated in three phases:
All findings were responsibly disclosed to maintainers; 18 have been patched as of March 2026.
Notable Vulnerabilities
1. Intent Redirection in a Popular File Manager (CVE-2026-XXXX)
A malicious app could trick the file manager into granting access to arbitrary files via a crafted intent, leading to data exfiltration.
2. Use-After-Free in a Media Codec Library (CVE-2026-YYYY)
Native heap corruption allowed denial-of-service or potential code execution when processing malformed MP4 files.
3. Insecure WebView JavaScript Bridge in a Banking App (CVE-2026-ZZZZ)
The agent found a bridge that exposed sensitive device APIs to untrusted web content.
Lessons Learned
Future Work
In 2026, we plan to extend the agent to support Android's new modular system components (Project Treble evolution) and to integrate with real-time threat intelligence feeds. We also aim to reduce the validation time from hours to minutes using lightweight containerization.
Get Involved
The agent is available on GitHub: github.com/kwstubbs/ai-android-agent. Contributions welcome.
Kevin Stubbings is a security researcher and open source maintainer. Follow him on GitHub @kwstubbs.
via GitHub AI Blog
