Saltar al contenido principal
Volver a noticias
vulnerabilities The Hacker News Verificada

Agentes de inteligencia artificial de código abierto para Android podrían ejecutar código en PCs anfitriones a través de texto de pantalla invisible

android ai vulnerabilidades ciberseguridad agentes

Resumen

Investigadores han demostrado que aplicaciones de Android pueden enviar instrucciones a agentes de inteligencia artificial en el teléfono, lo que puede permitir la ejecución de comandos en PCs anfitriones. Esto se logra a través de una cadena de ataques que incluye la capacidad de dibujar sobre otras ventanas y escribir en almacenamiento compartido. Los investigadores han identificado vulnerabilidades en cinco frameworks de agentes móviles de código abierto.

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,

CompartirXin

Noticias relacionadas