EngageLab SDK flaw opens door to private data on 50M Android devices
ID: 20fab64e-9ab2-53e7-89c4-c664f721c648
STIX ID: report--20fab64e-9ab2-53e7-89c4-c664f721c648
Feed Name: Security Affairs
Threat Score
Microsoft disclosed a critical intent-redirection flaw in the EngageLab SDK (v4.5.4) that could let a malicious app trick vulnerable apps into sending intents with the target app’s privileges, bypassing Android sandbox protections and exposing private data; the issue affected an estimated 50M installs (including ~30M crypto wallet installs), was fixed in EngageLab v5.2.1, and no active exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
