Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
Summary
Researchers discovered seven attacks against five open-source Android AI agent frameworks (AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA) that could let malicious apps trick the AI into running commands on a host PC. The attacks exploit weaknesses like invisible text overlays that AI vision models can read but humans cannot, file race conditions (timing gaps where attackers can modify screenshots before the AI sees them), and unsanitized shell commands that allow code injection when the AI types attacker-controlled text.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Original source: https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
First tracked: July 21, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%