EngageSDK Vulnerability Exposes Millions of Crypto Wallet Users to Cyberattacks
ID: f871c926-53c4-58ab-9924-fb7b17770ec4
STIX ID: report--f871c926-53c4-58ab-9924-fb7b17770ec4
Feed Name: cybersecurityNews.com
A critical intent-redirection vulnerability in the EngageSDK Android library (MTCommonActivity) allowed malicious apps on the same device to craft URIs that the SDK would convert into intents with elevated permissions, potentially granting persistent read/write access to private app storage and exposing crypto wallet credentials; the flaw affected over 30 million crypto wallet installs (50M+ total), was reported by Microsoft, and was fixed in EngageLab SDK v5.2.1 with Android deploying automatic mitigations while developers update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
