negativeSYS.SOURCE: The Hacker News• 2026-07-21T17:28:00+05:30
Vulnerabilities in Open-Source Android AI Agents Enable Host Code Execution via Stealthy Text Injection
Researchers identified vulnerabilities in five open-source Android AI frameworks allowing code execution on host PCs through stealthy text injection and command injection. The exploits leverage file race conditions, accessibility services, and insecure ADB interactions, with no CVEs reported yet.
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.
Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,
*** END OF TRANSMISSION ***