He and his research student Hong Kai Chen applied these techniques to a study on OpenHarmony, the open-source foundation behind parts of Huawei’s commercial HarmonyOS ecosystem for mobile devices.
“We found dozens of flaws, ranging from Bluetooth, device takeovers, to privacy leaks, location, all of this, very fun stuff, in Open Harmony, because we started from the vulnerability properties that we extracted from Android bugs,” Shoshitaishvili said. “Now we’re doing this agentically, and the results are incredible.”
With agentic pipelines, Shoshitaishvili’s team is finding vulnerabilities far faster than they can responsibly disclose with accompanying documentation and proposed fixes.