Coding Mistake Left Six Microsoft 365 Android Apps Vulnerable to Account Takeover
Want more insights like this?
A debug setting accidentally left enabled in production releases of six Microsoft Android apps — Word, Excel, PowerPoint, OneNote, Loop and 365 Copilot — exposed billions of users to potential account takeover. Researchers at Enclave, who named the issue FlagLeft, found the flaw disabled a security check that prevents untrusted apps from grabbing Microsoft authentication tokens.
Any malicious Android app could silently request and receive login tokens, giving attackers access to emails, Teams messages and files. Worse, the stolen tokens were long-lived FOCI (Family of Client IDs) tokens that can be refreshed indefinitely and look identical to legitimate activity in logs, making detection nearly impossible.
Microsoft has patched all six apps, assigning CVE-2026-41100, CVE-2026-41101, CVE-2026-41102 and CVE-2026-42832. There's no confirmation the flaw was exploited before it was found — but if you have any of these apps installed, update them now.
Source: Dark Reading