The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers found that several open-source Android AI agent frameworks can be tricked into running commands on the operator's PC, using invisible on-screen text, manipulated screenshots, and unfiltered shell inputs.
- All five tested frameworks — AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA — fell to at least six of seven demonstrated attacks, though no evidence of real-world exploitation exists.
- The maintainers were notified privately but had not responded, no CVEs have been assigned, and vulnerable code remains on the main branches.
- The attacks require a malicious app installed, an agent mid-task, and debugging enabled, but some need minimal or no Android permissions.
What to watch next
- Whether maintainers of the five frameworks respond and patch the shell-injection and screenshot paths
- Whether CVEs are assigned and fixes land on the frameworks' main branches
- Whether the techniques appear outside controlled lab settings
Coverage1
1 report
English national1
All filed from India
Named China · Hong Kong SAR China · Canada · AppAgent · AppAgentX · Claude Opus 4.5 · Gemini 3 Pro · GLM-4V · GPT-4o · MobA · Mobile-Agent-v3 · Open-AutoGLM · Chinese University of Hong Kong · QAX · Shandong University
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
