logo

EngageSDK Vulnerability Exposes Millions of Crypto Wallet Users to Cyberattacks

ID: f871c926-53c4-58ab-9924-fb7b17770ec4

STIX ID: report--f871c926-53c4-58ab-9924-fb7b17770ec4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical intent-redirection vulnerability in the EngageSDK Android library (MTCommonActivity) allowed malicious apps on the same device to craft URIs that the SDK would convert into intents with elevated permissions, potentially granting persistent read/write access to private app storage and exposing crypto wallet credentials; the flaw affected over 30 million crypto wallet installs (50M+ total), was reported by Microsoft, and was fixed in EngageLab SDK v5.2.1 with Android deploying automatic mitigations while developers update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.