SECURITY·중요도 8·2026. 07. 21.·The Hacker News

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

── KO ──────────────────

안드로이드 AI 에이전트를 이용한 보안 취약점 공격 시연.

연구자들은 안드로이드 애플리케이션을 사용하여 보이지 않는 화면 텍스트를 통해 PC에서 코드를 실행하는 공격 방법을 시연했습니다. 이 공격은 AppAgent, AppAgentX 등 다섯 개의 오픈 소스 모바일 에이전트 프레임워크에 대해 적용되었습니다. 보안의 취약점은 AI 에이전트를 통해 원격으로 기기를 제어할 수 있는 가능성을 나타내며, 이는 심각한 보안 위협이 될 수 있습니다.


── EN ──────────────────

Demonstration of security vulnerabilities using Android AI agents.

Researchers demonstrated a method to execute commands on host PCs via invisible screen text using an Android app. This attack was demonstrated against five open-source mobile agent frameworks, including AppAgent and AppAgentX. The identified security vulnerabilities reveal the potential to control devices remotely through AI agents, posing significant security threats.

원문 보기 →목록으로