news.mlab.sh
2 results
vulnerability

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

A vulnerability in Microsoft 365 Android apps allowed unauthorized apps to steal user account tokens, potentially granting access to sensitive data like emails and calendar information. The flaw, discovered by Enclave, stemmed from a debug flag left enabled in production builds, and Microsoft has since released patches…

The Hacker News · Jun 3, 2026 High