URL has been copied successfully!
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps.Any other app on the same phone could ask for the signed-in user’s token and get it, then read email, open files, browse the calendar, and send messages as that user. No password, no login screen, no permission prompt.

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link