EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
ID: 08eecc78-708c-5e80-9f49-1383ad6283ff
STIX ID: report--08eecc78-708c-5e80-9f49-1383ad6283ff
Feed Name: The Hacker News
Microsoft Defender disclosed a now-patched intent-redirection vulnerability in the EngageLab Android SDK that could let malicious apps on the same device bypass Android's sandbox and access sensitive data from apps (notably cryptocurrency wallet apps). The flaw (in SDK v4.5.4) potentially affected wallet apps with over 30 million installs and 50+ million installations when including non-wallet apps; EngageLab released v5.2.1 in November 2025 following responsible disclosure, and no active exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
