logo

EngageSDK Flaw Exposes 50 Million Android Users to Data Theft

ID: 46c846fb-619a-5aef-84f6-ca809949a709

STIX ID: report--46c846fb-619a-5aef-84f6-ca809949a709

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Defender found a severe intent redirection vulnerability in the widely used EngageSDK (formerly EngageLab) for Android that could let a co-resident malicious app trick MTCommonActivity to access private app storage. The flaw impacted over 30 million crypto wallet installs and more than 50 million total app installations, risking PII, credentials, and financial data. EngageSDK 5.2.1 (released 2025-11-03) fixes the issue by setting the activity to non-exported; Microsoft reported no known exploitation in the wild and affected apps were removed from Google Play.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.