Close Menu
    What's Hot

    Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

    Uber lays off 23% of its HR and recruiting team that became ‘too complex and fragmented’

    The Narrow Path to a Democratic Senate Runs Through Very Red States

    Facebook X (Twitter) Instagram
    Trending
    • Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
    • Uber lays off 23% of its HR and recruiting team that became ‘too complex and fragmented’
    • The Narrow Path to a Democratic Senate Runs Through Very Red States
    • Elon Musk’s SpaceX eyes $1.77tn valuation ahead of historic IPO | Technology News
    • Israel and Lebanon Renew Cease-Fire, Calling for Evacuation of Hezbollah Operatives
    • Your Business Could Lose More Than Its Founder If You’re Suddenly Incapacitated
    • Pace Gallery Cuts 50 Artists and 50 Staff Amid Art Market Challenges
    • Flesh-Eating Pest Confirmed in U.S. Cattle
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

    adminBy adminJune 4, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJun 03, 2026Vulnerability / Mobile Security

    Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

    A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps.

    Any other app on the same phone could ask for the signed-in user’s token and get it, then read email, open files, browse the calendar, and send messages as that user. No password, no login screen, no permission prompt.

    Microsoft has patched it, and if you run Microsoft 365 apps on Android, update them.

    The bug, which Enclave calls FlagLeft, hit Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote, six apps with billions of downloads between them. Teams shipped with the same flag set to false and were not affected, which Enclave reads as a slip rather than a design.

    Cybersecurity

    Microsoft 365 apps share account access on purpose, so signing into Word means you do not sign in again for PowerPoint. The handoff is supposed to verify who is asking and turn away anything that is not a trusted Microsoft app.

    Enclave’s Yanir Tsarimi and Ofek Levin found the check was being skipped because of a single line left in the shipping code: setIsDebugMode(true). The flaw sat in a shared Microsoft SDK, so the same hole showed up in app after app.

    The tokens handed over were FOCI tokens, the family refreshes tokens Microsoft uses for single sign-on across its apps. They can be refreshed and reused over long stretches, and the resulting traffic looks routine in logs. From the user’s side, nothing visible happens.

    Enclave built a working proof of concept that pulled tokens through an unverified third-party app and read email with them. Microsoft classifies these as local spoofing flaws; in plain terms, a malicious app already on the device is all it takes.

    Microsoft issued four CVEs on May 12, all classed as spoofing under improper access control (CWE-284): CVE-2026-41100 for Microsoft 365 Copilot (CVSS 4.4), CVE-2026-41101 for Word (CVSS 7.1), CVE-2026-41102 for PowerPoint (CVSS 7.1), and CVE-2026-42832 for Excel (CVSS 7.7). The four CVEs cover Copilot, Word, PowerPoint, and Excel.

    Enclave reported the same flaw in Loop and OneNote, but neither got a separate CVE in the May batch. NVD lists the patched Word build for Android as 16.0.19822.20190, with earlier versions affected. The other apps were fixed through the same Google Play updates.

    Cybersecurity

    Nothing in Microsoft’s May Patch Tuesday release was listed as publicly known or exploited, and there is no public evidence that the flaw was used before the fix.

    What to do? Update Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote from Google Play. Security teams managing Android fleets should push the updates through MDM and confirm devices are off builds earlier than 16.0.19822.20190.

    The patch closes the hole, but it does not retroactively kill tokens that an attacker may already hold. FOCI refresh tokens outlive an app update, so for accounts on devices that ran an old build alongside untrusted apps, it is worth revoking refresh tokens and forcing a fresh sign-in.

    account Android app apps Debug Flag leftover Microsoft steal Tokens
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleNBA Finals 2026: How to watch Game 1 of the Knicks vs. Spurs, live online or on TV, including free options
    Next Article Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
    admin
    • Website

    Related Posts

    Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

    June 4, 2026

    Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

    June 3, 2026

    WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

    June 3, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

    Uber lays off 23% of its HR and recruiting team that became ‘too complex and fragmented’

    The Narrow Path to a Democratic Senate Runs Through Very Red States

    Elon Musk’s SpaceX eyes $1.77tn valuation ahead of historic IPO | Technology News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by