logo

Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk

ID: 1fdb2220-db40-5e00-a04c-cd24713c0a65

STIX ID: report--1fdb2220-db40-5e00-a04c-cd24713c0a65

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender Security Research discovered a severe intent redirection vulnerability in the EngageLab Android SDK (MTCommonActivity) that could allow a malicious app to cause vulnerable apps to send intents under their identity, potentially granting persistent read/write access to private content providers and exposing sensitive PII and financial data. The flaw affected a large portion of the mobile wallet ecosystem (over 30 million wallet installs and >50 million total installs across apps), was reported via coordinated disclosure, and addressed in EngageSDK v5.2.1 (Nov 3, 2025); no evidence of active exploitation was observed, and developers are strongly advised to update and review merged manifests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.