enclave.ai Microsoft 365 Android Apps Vulnerability Exposes User Accounts to Takeover
Article Content
- •A debug flag in Microsoft 365 Android apps allowed unauthorized access to user tokens.
- •The vulnerability, dubbed FlagLeft, affected billions of users across six major apps.
- •Microsoft has released patches; users must update their apps to mitigate the risk.
A coding error in Microsoft 365 Android applications allowed unauthorized apps to access user account tokens, leading to potential account takeovers. This vulnerability, known as FlagLeft, was due to a debug flag left enabled in production code across six major apps, including Word and Excel. Attackers could exploit this by installing a malicious app on the same device, which could silently request and receive Microsoft account tokens without user consent. The issue affected billions of users, as any app on the device could gain access to sensitive information like emails and files. Microsoft has since patched the vulnerability, and users are urged to update their apps immediately. The vulnerability was associated with CVEs published on May 12, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Enclave and CVE-2026-41100 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…