{"data":{"id":"b2a6a49b-0d23-4217-b858-c8c87b988cee","title":"Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs","summary":"Researchers discovered seven attacks against five open-source Android AI agent frameworks (AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA) that could let malicious apps trick the AI into running commands on a host PC. The attacks exploit weaknesses like invisible text overlays that AI vision models can read but humans cannot, file race conditions (timing gaps where attackers can modify screenshots before the AI sees them), and unsanitized shell commands that allow code injection when the AI types attacker-controlled text.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html","publishedAt":"2026-07-21T11:58:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection","model_evasion"],"issueType":"news","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["AppAgent","AppAgentX","Mobile-Agent-v3","Open-AutoGLM","MobA","GPT-4o","Claude Opus 4.5","Gemini 3 Pro","GLM-4V","AutoGLM-Phone"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-21T11:58:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}