
Mobile MCP patches arbitrary Android intent execution via URL schemes
A GitHub-reviewed advisory warns @mobilenext/mobile-mcp users that unvalidated URL schemes in mobile_open_url allow prompt-injected AI agents to trigger arbitrary Android intents via ADB.
NewsMobile SecurityAI Security
2 minYesterday

