threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabled security setting that allowed unauthorized apps to request authentication tokens, enabling attack… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
vulnerability Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A vulnerability in Microsoft 365 Android apps allowed unauthorized apps to steal user account tokens, potentially granting access to sensitive data like emails and calendar information. The flaw, discovered by Enclave, s… The Hacker News · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102androidtokenspoofing