logo

EngageSDK Vulnerability puts millions of crypto wallets at risk

ID: 082e7d60-80b2-5933-8321-7c6202f1b7ed

STIX ID: report--082e7d60-80b2-5933-8321-7c6202f1b7ed

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A critical intent-redirection vulnerability in the EngageSDK Android library could allow malicious apps to exploit an exported SDK activity to bypass sandbox protections and access PII, credentials, and cryptocurrency wallet data across millions of installs; Microsoft disclosed the issue (affecting v4.5.4) and the SDK was patched in v5.2.1—developers must update and audit merged Android manifests to remove unintended exported components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.