logo

Microsoft: Third-Party Android Vulnerability Leaves Over 50M Users Exposed

ID: f943a292-07ec-51fd-9e83-5b1bc5a918c8

STIX ID: report--f943a292-07ec-51fd-9e83-5b1bc5a918c8

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Joseph Ofonagoro

...
...

A critical intent-redirection vulnerability in the widely used EngageLab Android SDK allowed unprivileged, malicious apps to send crafted intents to exported SDK components and have those intents executed with the host app’s permissions, risking access to private files and exfiltration of sensitive data (notably crypto wallet keys). Microsoft discovered the flaw, coordinated disclosure with EngageLab (patch v5.2.1) and Android/Google removed flagged apps; over 50 million installs were affected but no known in-the-wild exploitation had been observed as of April 9, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.