AppAgent: Open-Source Android AI Agent Framework
An open-source framework for AI agents on Android. Vulnerable to command injection and screenshot tampering attacks as demonstrated in recent research.
An open-source framework for AI agents on Android. Vulnerable to command injection and screenshot tampering attacks as demonstrated in recent research.
An open-source Android AI agent framework found vulnerable to multiple attack vectors including invisible text injection and host command execution.
An open-source mobile AI agent framework vulnerable to screenshot tampering, command injection, and credential theft via overlay attacks.
An open-source Android AI agent framework with over 25,000 GitHub stars. Vulnerable to multiple attacks including broadcast interception and command injection.
An open-source Android AI agent framework that streams screenshots over exec-out, avoiding file race conditions, but still vulnerable to other attack vectors.
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
COWARDDUCK is a full-featured Android backdoor distributed via messaging apps, disguised as security tools. It exfiltrates contacts, files, and geolocation using Dropbox…
The European Commission has adopted binding specification decisions under the Digital Markets Act, requiring Google to open Android features to rival AI…
The IonStack exploit chain uses CVE-2026-10702 and CVE-2026-43499 to achieve remote code execution and root on Android 17 devices.