Back Feeds.4Sysops Microsoft 365 Android apps exposed account tokens via debug flag
A development flag accidentally left active in several Microsoft 365 Android applications allowed unauthorized apps to bypass security checks and harvest account access tokens. This vulnerability, dubbed FlagLeft, originated from a single line of code in a shared software development kit that disabled identity verification for cross-app communication. Because the "isDebugMode" flag was set to true, any malicious application on the same device could request and receive tokens without user interaction or password prompts. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
