news.mlab.sh
Back to the feed
vulnerability

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

High
Summary

A vulnerability in Microsoft 365 Android apps allowed unauthorized apps to steal user account tokens, potentially granting access to sensitive data like emails and calendar information. The flaw, discovered by Enclave, stemmed from a debug flag left enabled in production builds, and Microsoft has since released patches. Users are advised to update their apps to mitigate the risk.

The security issue, dubbed ‘FlagLeft,’ impacted several Microsoft 365 Android applications including Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote. The vulnerability allowed any installed app on the device to request and obtain the user’s account token, bypassing standard authentication processes. This enabled the malicious app to perform actions such as reading emails, accessing files, and sending messages as the user, without requiring a password or permission prompt. Microsoft addressed the issue with four CVEs, classifying it as a spoofing flaw under improper access control. Users are advised to update their apps immediately and security teams should enforce updates through MDM.

Read the full article at The Hacker News