A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on the same phone could ask for the signed-in user's token and get it, then read email, open files, browse the
โก
Key Insights
10 editorial insights.
AiFeed24 Teamยทโฑ 1 min readยทSecurity
Deep Analysis
Multi-Source Intelligence
Tags:#security
Found this useful? Share it!
Related Stories
๐
๐Security
Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5
about 2 hours ago

๐Security
Sprawling new House AI bill includes frontier model oversight, open-source security grants
about 4 hours ago
๐
๐Security
OWASP's New Tool Enables Rapid Detection and Resolution of Vulnerable Dependencies
about 2 hours ago
๐
๐Security
Critical US Gas Stations Exposed: Vulnerable Tank Gauges Leave Door Open to Hackers
about 4 hours ago
