Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 Android Apps Vulnerability Allows Token Theft

Microsoft 365 Android Apps Vulnerability Allows Token Theft

Posted on June 3, 2026 By CWS

Microsoft has recently addressed a critical vulnerability in several of its 365 Android applications that previously allowed unauthorized applications to gain access to account tokens of signed-in users. This issue, which was rooted in a leftover debug flag, affected popular apps such as Word, PowerPoint, Excel, Copilot, Loop, and OneNote, necessitating users to update their apps immediately to protect their accounts.

Security Flaw Details

The flaw was discovered in production builds of these apps, where a development flag unintentionally left active disabled the restriction that should have limited account token sharing to verified Microsoft applications only. Consequently, any third-party app on the same device could request and obtain these tokens, enabling them to access emails, files, calendar events, and more without any user authentication or prompt.

Enclave, the security firm that uncovered this vulnerability, dubbed it ‘FlagLeft’. The issue was attributed to a single line in the code: setIsDebugMode(true), which bypassed essential security checks. Notably, Microsoft Teams was not impacted due to the debug flag being correctly set to false.

Impact and Resolution

Microsoft’s suite of applications uses FOCI tokens to facilitate single sign-on across its platforms. These tokens, which can be refreshed and reused over extended periods, make user activity appear normal, thus potentially obscuring unauthorized access. Enclave demonstrated the vulnerability through a proof of concept, showing how a malicious app could exploit this flaw.

In response, Microsoft released fixes for the affected applications via Google Play updates. On May 12, four Common Vulnerabilities and Exposures (CVEs) were issued, highlighting the severity of the issue. These include CVE-2026-41100 for Copilot, CVE-2026-41101 for Word, CVE-2026-41102 for PowerPoint, and CVE-2026-42832 for Excel. Although similar flaws were present in Loop and OneNote, these apps did not receive individual CVEs in the May update.

Preventive Measures and Recommendations

While Microsoft has patched the vulnerability, the old tokens that attackers might already possess are not automatically invalidated. It is crucial for users and security teams to update their Microsoft 365 apps promptly. For organizations managing Android devices, deploying updates via Mobile Device Management (MDM) systems is recommended to ensure all devices run the latest secure versions.

Furthermore, it’s advisable for users to revoke any existing refresh tokens and initiate new sign-ins, particularly on devices that previously operated outdated app versions alongside untrusted applications. This precaution helps mitigate risks associated with potential token theft.

Overall, staying vigilant with software updates and security practices remains essential in safeguarding personal and organizational data against such vulnerabilities.

The Hacker News Tags:Android security, app security, app vulnerability, Cybersecurity, debug flag, FOCI tokens, Microsoft 365, mobile security, software update, token theft

Post navigation

Previous Post: HazyBeacon Exploits AWS for Covert Cyber Operations
Next Post: Gentlemen Ransomware Exploits Fortinet and AI Tactics

Related Posts

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow The Hacker News
How to Address the Expanding Security Risk How to Address the Expanding Security Risk The Hacker News
Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans The Hacker News
GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools The Hacker News
CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign The Hacker News
Exploitation of TrueConf Flaw Targets Southeast Asian Governments Exploitation of TrueConf Flaw Targets Southeast Asian Governments The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark