Microsoft Android App Debug Flaw Exposed Billions of Installs
TL;DR. A single debug flag in six Microsoft 365 Android apps could have allowed untrusted apps to access user account tokens. - This flaw bypassed token sharing protections, affecting billions of app installations. - An Enclave AI-powered bug hunter uncovered the vulnerability, exposing an oversight in production code. - Attackers could have exploited the open debug mode with a simple 15-line code snippet.
- Six Microsoft 365 Android apps (Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, OneNote) contained a debug mode flaw.
- The vulnerability allowed untrusted Android apps to access Microsoft account tokens due to a skipped protection.
- Enclave, an AI-powered exploitable bug hunter, discovered the issue before public release.
- An attacker could have exploited this with minimal code to gain unauthorized access to user tokens.