AIBearisharXiv โ CS AI ยท 5h ago0
๐ง
Zero-Permission Manipulation: Can We Trust Large Multimodal Model Powered GUI Agents?
Researchers discovered a critical security vulnerability in AI-powered GUI agents on Android, where malicious apps can hijack agent actions without requiring dangerous permissions. The 'Action Rebinding' attack exploits timing gaps between AI observation and action, achieving 100% success rates in tests across six popular Android GUI agents.