Skip to content
Microsoft 365 Android apps exposed account tokens via debug flag

Microsoft 365 Android apps exposed account tokens via debug flag

Feeds.4Sysops IT News June 3, 2026

A development flag accidentally left active in several Microsoft 365 Android applications allowed unauthorized apps to bypass security checks and harvest account access tokens. This vulnerability, dubbed FlagLeft, originated from a single line of code in a shared software development kit that disabled identity verification for cross-app communication. Because the "isDebugMode" flag was set to true, any malicious application on the same device could request and receive tokens without user interaction or password prompts. Source

Extracted Entities

Attack Types (1)

Platforms (1)

Vulnerabilities (1)