logo

Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover

ID: 0a028edf-4772-55f5-a1b9-fad71bc45e43

STIX ID: report--0a028edf-4772-55f5-a1b9-fad71bc45e43

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-15

Author: Elizabeth Montalbano

...
...

Researchers discovered a debug/test setting mistakenly left enabled in six Microsoft Android apps (Word, OneNote, PowerPoint, Excel, Loop, and 365 Copilot) and in a shared SDK, which allowed untrusted apps to request and receive reusable FOCI authentication tokens without validating the requester; a malicious Android app could silently exfiltrate those tokens and access email, Teams messages, and files across Microsoft 365 apps. Microsoft issued patches and multiple CVEs (CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, CVE-2026-42832) after responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.