Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Android Crypto Wallets at Risk Due to SDK Flaw

Android Crypto Wallets at Risk Due to SDK Flaw

Posted on April 10, 2026 By CWS

Microsoft’s cybersecurity team has identified a significant vulnerability within a third-party SDK that poses a threat to millions of Android cryptocurrency wallet users. The flaw, found in EngageLab’s EngageSDK, can potentially expose sensitive data due to its widespread use in managing messaging and push notifications.

Details of the EngageSDK Flaw

The vulnerability resides in the EngageSDK, a tool integrated by developers into Android applications. This SDK is prevalent in cryptocurrency wallet apps, boasting more than 30 million installations. The flaw involves Android intents, which are used for inter-application communication and data sharing.

Microsoft researchers have pinpointed an intent redirection issue, allowing attackers to manipulate intents sent by compromised applications. This manipulation can be exploited by a malicious app on the same device, enabling it to bypass Android’s security measures and access sensitive information such as personal data and financial details.

Response and Mitigation Efforts

Upon discovering the vulnerability, Microsoft informed EngageLab in April 2025, followed by a notification to the Android Security Team in May due to potential impacts on apps available via Google Play. Despite being a third-party issue, Android’s multi-layered security model offers additional protections against such vulnerabilities.

All affected crypto wallet applications have since been removed from Google Play. Furthermore, Android’s security measures are expected to shield users who have previously downloaded impacted versions. EngageLab addressed the flaw with a patch released in November 2025, updating the SDK to version 5.2.1.

Current Status and Recommendations

Microsoft has publicly shared technical details of the vulnerability to alert developers about the importance of using the latest SDK version. Fortunately, there is no evidence to suggest that this vulnerability has been exploited in practice.

Developers are urged to update their applications promptly to mitigate any potential security risks. Users are encouraged to ensure their apps are up-to-date and to remain vigilant about app permissions and sources.

The discovery underscores the importance of regular security assessments and updates in protecting digital assets, particularly in the financial technology sector.

Security Week News Tags:Android, Android intents, app security, crypto wallets, Cybersecurity, data protection, EngageLab, EngageSDK, Google Play, Microsoft, mobile apps, Patch, SDK, Security, Vulnerability

Post navigation

Previous Post: 5,219 PLCs at Risk from Iranian Cyber Threats, Censys Reports
Next Post: Exposed GitHub Copilot Flaw Risks Sensitive Data

Related Posts

Jazz Secures M to Revolutionize AI-Powered DLP Jazz Secures $61M to Revolutionize AI-Powered DLP Security Week News
CISO Conversations: Are Microsoft’s Deputy CISOs a Signpost to the Future? CISO Conversations: Are Microsoft’s Deputy CISOs a Signpost to the Future? Security Week News
Microsoft Addresses Six Zero-Day Vulnerabilities in February 2026 Update Microsoft Addresses Six Zero-Day Vulnerabilities in February 2026 Update Security Week News
The Root of AI Hallucinations: Physics Theory Digs Into the ‘Attention’ Flaw The Root of AI Hallucinations: Physics Theory Digs Into the ‘Attention’ Flaw Security Week News
MATLAB Maker MathWorks Recovering From Ransomware Attack MATLAB Maker MathWorks Recovering From Ransomware Attack Security Week News
MITRE Unveils ATT&CK v18 With Updates to Detections, Mobile, ICS MITRE Unveils ATT&CK v18 With Updates to Detections, Mobile, ICS Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cloud Atlas APT Exploits Windows for Multiple RDP Sessions
  • North Korean Malware Evades Detection with New Tactics
  • Russian Hacker Exploits Google Gemini for Crypto Theft
  • Cybercriminals Exploit Telegram for Selling Bank Mule Accounts
  • Linux Attack Hides Malicious Payload in Package Installs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cloud Atlas APT Exploits Windows for Multiple RDP Sessions
  • North Korean Malware Evades Detection with New Tactics
  • Russian Hacker Exploits Google Gemini for Crypto Theft
  • Cybercriminals Exploit Telegram for Selling Bank Mule Accounts
  • Linux Attack Hides Malicious Payload in Package Installs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark