Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

General News

Summary

Microsoft fixed a set of Android app vulnerabilities caused by a debug flag left enabled in production across six Microsoft 365 apps. The flaw could have allowed untrusted Android apps to receive Microsoft access tokens and access user data such as email, files, documents, and calendar information. Enclave reported the issue, Microsoft confirmed it, and the company assigned CVEs and pushed patches through its normal update channels. The incident shows how a small development mistake can create a broad security exposure across major software products.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
SaaS Cloud Computing Enterprise Software

Linked Companies

Microsoft
$1B+