logo

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

ID: 209fe629-6c15-5ce8-8c8e-093fd1cacce9

STIX ID: report--209fe629-6c15-5ce8-8c8e-093fd1cacce9

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

Author: [email protected] (The Hacker News)

...
...

Multiple Microsoft 365 Android apps (Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote) shipped with a development flag that disabled the check limiting account-token sharing to trusted apps, allowing any malicious app on the same device to request and receive FOCI tokens and access email, files, calendar, and messages without authentication. Enclave produced a proof-of-concept, Microsoft issued CVEs and patches (patched builds available via Google Play), and recommended updating affected apps, pushing updates via MDM, and revoking refresh tokens for devices that ran affected builds alongside untrusted apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.