← Back to news

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

SecurityWeek02/06/2026, 15:00
Read full article →

Summary

AI-Generated

Key Points:

  • A critical vulnerability exists in six Microsoft 365 Android apps due to a debug flag left enabled, allowing unauthorized access to Microsoft account tokens.
  • The flaw affects Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote, potentially compromising billions of downloads by enabling any Android app to request and receive access tokens.
  • Immediate patching is recommended for affected users to secure their accounts; users should ensure their apps are updated with the latest security fixes.

Technical Details: The vulnerability is identified as CVE-2026-41100, -41101, and -41102. It allows attackers to exploit the debug mode in production code by writing a small snippet of code that requests access tokens from the vulnerable apps.

MITRE ATT&CK Techniques:

  • None mentioned

IOCs Mentioned:

  • CVE-2026-41100
  • CVE-2026-41101
  • CVE-2026-41102

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.