Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover
ID: 0a028edf-4772-55f5-a1b9-fad71bc45e43
STIX ID: report--0a028edf-4772-55f5-a1b9-fad71bc45e43
Feed Name: Dark Reading
Researchers discovered a debug/test setting mistakenly left enabled in six Microsoft Android apps (Word, OneNote, PowerPoint, Excel, Loop, and 365 Copilot) and in a shared SDK, which allowed untrusted apps to request and receive reusable FOCI authentication tokens without validating the requester; a malicious Android app could silently exfiltrate those tokens and access email, Teams messages, and files across Microsoft 365 apps. Microsoft issued patches and multiple CVEs (CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, CVE-2026-42832) after responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
