Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Microsoft 365 Android Apps Risked User Accounts

Critical Flaw in Microsoft 365 Android Apps Risked User Accounts

Posted on June 3, 2026 By CWS

A significant security vulnerability in Microsoft 365 Android apps exposed billions of users to potential account takeovers. The flaw, known as FlagLeft, allowed unauthorized access to account tokens across six major apps, posing a substantial risk to user data and privacy.

Understanding the FlagLeft Vulnerability

The vulnerability stemmed from a development oversight where a debug flag, setIsDebugMode(true), was left active in production code. This flag disabled the authorization checks, enabling any third-party app on the same device to request and obtain valid Microsoft account tokens without user consent or notification.

These tokens are part of Microsoft’s FOCI mechanism, designed to facilitate seamless single sign-on across apps like Word, PowerPoint, and Excel. However, with the debug mode active, this trust mechanism was bypassed, allowing unauthorized apps to impersonate legitimate Microsoft applications.

Impact on Microsoft 365 Android Apps

The affected apps included Microsoft Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and Microsoft OneNote. The flaw was traced to a shared Microsoft SDK, which propagated the issue across these applications.

While Microsoft Teams remained unaffected due to a correctly configured debug flag, the vulnerability allowed attackers to access sensitive user data such as emails, files, and calendar events. This posed a significant threat as the tokens are long-lived and generate no abnormal activity, making detection difficult.

Response and Mitigation Measures

Upon discovery, Microsoft acted swiftly to patch the vulnerability across all affected apps. The company assigned CVEs to the issues, with varying severity scores, and urged users to update their apps to the latest versions.

Enterprise administrators were advised to ensure that updated versions are deployed across managed devices and to audit token activities for any anomalies using Microsoft Defender for Cloud Apps. This situation highlighted the importance of rigorous code reviews to prevent such oversights in production environments.

Research conducted by Enclave and Ofek Levin played a crucial role in identifying the vulnerability’s scope. Their work underscores the potential impact of a single line of code on global cybersecurity, emphasizing the need for vigilant security practices.

Conclusion

This incident serves as a stark reminder of the fragility of software security and the far-reaching consequences of development errors. As Microsoft continues to address the fallout, users and organizations alike are encouraged to remain vigilant and proactive in maintaining app security and updates.

Cyber Security News Tags:account takeover, Android, CVE, debug flag, Enclave, FOCI, Microsoft 365, Microsoft apps, Ofek Levin, SDK, security flaw, security patch, token theft, Vulnerability

Post navigation

Previous Post: Microsoft Addresses Concerns Over Zero-Day Vulnerability Disclosures
Next Post: Unresolved Windows Search Vulnerability Risks NTLMv2 Hash Theft

Related Posts

Critical Flaw in API Keys Plugin Enables Account Takeovers Critical Flaw in API Keys Plugin Enables Account Takeovers Cyber Security News
Hundreds of WordPress Websites Hacked By VexTrio Viper Group to Run Massive TDS Services Hundreds of WordPress Websites Hacked By VexTrio Viper Group to Run Massive TDS Services Cyber Security News
Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware Cyber Security News
Apache Struts 2 DoS Vulnerability Let Attackers Crash Server Apache Struts 2 DoS Vulnerability Let Attackers Crash Server Cyber Security News
Linux Attack Hides Malicious Payload in Package Installs Linux Attack Hides Malicious Payload in Package Installs Cyber Security News
Threat Actors Leverage GenAI Platforms to Create Realistic Phishing Content Threat Actors Leverage GenAI Platforms to Create Realistic Phishing Content Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark