EngageSDK Flaw Exposes 50 Million Android Users to Data Theft
ID: 46c846fb-619a-5aef-84f6-ca809949a709
STIX ID: report--46c846fb-619a-5aef-84f6-ca809949a709
Feed Name: securityonline.info
Microsoft Defender found a severe intent redirection vulnerability in the widely used EngageSDK (formerly EngageLab) for Android that could let a co-resident malicious app trick MTCommonActivity to access private app storage. The flaw impacted over 30 million crypto wallet installs and more than 50 million total app installations, risking PII, credentials, and financial data. EngageSDK 5.2.1 (released 2025-11-03) fixes the issue by setting the activity to non-exported; Microsoft reported no known exploitation in the wild and affected apps were removed from Google Play.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
