Microsoft 365 Android Apps Vulnerability Exposes User Accounts to Takeover

Microsoft 365 Android Apps Vulnerability Exposes User Accounts to Takeover

First seen 3 Jun 2026, 21:09 UTC CybersecuritynewsDarkreadingenclave.aiFeeds.4SysopsRedmondmag+1 85% similarity 72.0

Article Content

Browse articles
ThreatCluster

A coding error in Microsoft 365 Android applications allowed unauthorized apps to access user account tokens, leading to potential account takeovers. This vulnerability, known as FlagLeft, was due to a debug flag left enabled in production code across six major apps, including Word and Excel. Attackers could exploit this by installing a malicious app on the same device, which could silently request and receive Microsoft account tokens without user consent. The issue affected billions of users, as any app on the device could gain access to sensitive information like emails and files. Microsoft has since patched the vulnerability, and users are urged to update their apps immediately. The vulnerability was associated with CVEs published on May 12, 2026.

Key Points: • A debug flag in Microsoft 365 Android apps allowed unauthorized access to user tokens. • The vulnerability, dubbed FlagLeft, affected billions of users across six major apps. • Microsoft has released patches; users must update their apps to mitigate the risk.

ThreatCluster AI

Timeline

2026-05-12
CVE-2026-41102 published
Microsoft disclosed vulnerabilities affecting Microsoft 365 Android apps, including the FlagLeft issue.
Darkreading
2026-05-12
CVE-2026-42832 published
Multiple vulnerabilities in Microsoft 365 Android apps were documented, including token exposure risks.
Darkreading
2026-05-12
CVE-2026-41101 published
Microsoft identified critical vulnerabilities in its Android applications that could lead to account takeovers.
Darkreading
2026-05-12
CVE-2026-41100 published
A series of vulnerabilities were disclosed by Microsoft, highlighting security flaws in their Android apps.
Darkreading
2026-06-03
Vulnerability patched
Microsoft released updates to address the FlagLeft vulnerability in its Android apps; users advised to update immediately.
enclave.ai

Community

Browse all →

Tracked Entities in This Story