vulnerability Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A vulnerability in Microsoft 365 Android apps allowed unauthorized apps to steal user account tokens, potentially granting access to sensitive data like emails and calendar information. The flaw, discovered by Enclave, stemmed from a debug flag left enabled in production builds, and Microsoft has since released patches… The Hacker News · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102androidtokenspoofing
vulnerability Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk A critical vulnerability was discovered in six Microsoft 365 Android apps – Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote – due to a debug flag left enabled in production code. This allowed… SecurityWeek · Jun 2, 2026 Critical CVE-2026-41100USdebugaccess tokensupply chain