Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
Summary
Microsoft fixed a set of Android app vulnerabilities caused by a debug flag left enabled in production across six Microsoft 365 apps. The flaw could have allowed untrusted Android apps to receive Microsoft access tokens and access user data such as email, files, documents, and calendar information. Enclave reported the issue, Microsoft confirmed it, and the company assigned CVEs and pushed patches through its normal update channels. The incident shows how a small development mistake can create a broad security exposure across major software products.
Classifications
industries
No industries detected
applications
Accounting and Taxes
AskAI Classifications
Labels
SaaS
Cloud Computing
Enterprise Software
Linked Companies
Microsoft
$1B+