enclave.ai
Microsoft 365 Android Apps Vulnerability Exposes User Accounts to Takeover
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A coding error in Microsoft 365 Android applications allowed unauthorized apps to access user account tokens, leading to potential account takeovers. This vulnerability, known as FlagLeft, was due to a debug flag left enabled in production code across six major apps, including Word and Excel. Attackers could exploit this by installing a malicious app on the same device, which could silently request and receive Microsoft account tokens without user consent. The issue affected billions of users, as any app on the device could gain access to sensitive information like emails and files. Microsoft has since patched the vulnerability, and users are urged to update their apps immediately. The vulnerability was associated with CVEs published on May 12, 2026.
Key Points: • A debug flag in Microsoft 365 Android apps allowed unauthorized access to user tokens. • The vulnerability, dubbed FlagLeft, affected billions of users across six major apps. • Microsoft has released patches; users must update their apps to mitigate the risk.