AppAgentX: Open-Source Android AI Agent Framework
An open-source Android AI agent framework found vulnerable to multiple attack vectors including invisible text injection and host command execution.
An open-source Android AI agent framework found vulnerable to multiple attack vectors including invisible text injection and host command execution.
An open-source mobile AI agent framework vulnerable to screenshot tampering, command injection, and credential theft via overlay attacks.
An open-source Android AI agent framework with over 25,000 GitHub stars. Vulnerable to multiple attacks including broadcast interception and command injection.
An open-source Android AI agent framework that streams screenshots over exec-out, avoiding file race conditions, but still vulnerable to other attack vectors.
A test automation tool for Android that accepts text via broadcast intents. Its documented functionality is exploited by AI agents for input,…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
COWARDDUCK is a full-featured Android backdoor distributed via messaging apps, disguised as security tools. It exfiltrates contacts, files, and geolocation using Dropbox…
The European Commission has adopted binding specification decisions under the Digital Markets Act, requiring Google to open Android features to rival AI…
The IonStack exploit chain uses CVE-2026-10702 and CVE-2026-43499 to achieve remote code execution and root on Android 17 devices.