<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Coding Mistake Left Six Microsoft 365 Android Apps Vulnerable to Account Takeover

Exposed debug setting in Microsoft Android apps risked account security by disabling token checks. Patch now available for affected apps.
Content Team

A debug setting accidentally left enabled in production releases of six Microsoft Android apps — Word, Excel, PowerPoint, OneNote, Loop and 365 Copilot — exposed billions of users to potential account takeover. Researchers at Enclave, who named the issue FlagLeft, found the flaw disabled a security check that prevents untrusted apps from grabbing Microsoft authentication tokens.

Any malicious Android app could silently request and receive login tokens, giving attackers access to emails, Teams messages and files. Worse, the stolen tokens were long-lived FOCI (Family of Client IDs) tokens that can be refreshed indefinitely and look identical to legitimate activity in logs, making detection nearly impossible.

Microsoft has patched all six apps, assigning CVE-2026-41100, CVE-2026-41101, CVE-2026-41102 and CVE-2026-42832. There's no confirmation the flaw was exploited before it was found — but if you have any of these apps installed, update them now.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo