CVE-2026-42832 is a vulnerability tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed June 3, 2026; most recent activity June 3, 2026.
A coding error in Microsoft 365 Android applications allowed unauthorized apps to access user account tokens, leading to potential account takeovers. This vulnerability, known as FlagLeft, was due to a debug flag left…