Microsoft 365 Android Apps Exposed User Tokens

Microsoft 365 Android Apps Hit by Security Flaw

Microsoft 365 Android Apps recently faced a serious security issue. Researchers discovered a development flag that remained active in production versions. As a result, the flaw weakened account protection on several Android apps.

The issue allowed untrusted apps to request account tokens. Therefore, attackers could gain access to sensitive user data. No password was required during the attack. Moreover, users received no warning or permission request.

Researchers reported the vulnerability to the vendor. However, there is no evidence that attackers exploited it before the fix. The affected apps have now received security updates. Therefore, users should install the latest versions immediately.

How the Vulnerability Worked

Microsoft applications often share login sessions. For example, signing into one productivity app also enables access to others. This design improves convenience for users. However, it depends on strict trust verification.

Normally, apps must prove they are trusted before receiving account tokens. Therefore, unauthorized applications should never gain access. Researchers discovered that this security check was accidentally disabled. As a result, any app on the same device could request tokens.

The problem originated from a debug setting. Developers typically use such settings during testing. However, one setting remained enabled in released versions. Consequently, the verification process was skipped completely.

Apps Affected by the Bug

The flaw impacted several popular Android applications. These included Word, Excel, PowerPoint, OneNote, Loop, and Copilot. Together, these apps have billions of downloads worldwide.

Researchers found the issue in a shared software component. Therefore, the same weakness appeared across multiple applications. Interestingly, Teams contained a similar setting. However, it was configured differently and remained protected.

Because the flaw existed in a shared toolkit, the impact became much broader. As a result, many users faced potential exposure. Fortunately, updates are now available through the official app store.

Why Account Tokens Matter

The stolen tokens were not ordinary credentials. Instead, they were long-lasting authentication tokens. These tokens help users stay signed in across applications. Because the tokens support single sign-on, they offer broad access. Therefore, attackers could read emails and open files. They could also view calendars and send messages. Moreover, these activities could appear legitimate in security logs.

Researchers created a proof-of-concept attack. For example, a malicious application successfully accessed email data. The attack required only a harmful app installed on the device. Therefore, local malware posed the greatest risk.

Security Updates and CVEs

The vendor addressed the flaw through several security updates. Researchers assigned multiple vulnerability identifiers to the issue. These vulnerabilities affected Word, Excel, PowerPoint, and Copilot.

Additional reports covered Loop and OneNote. However, those applications did not receive separate identifiers. The security updates were released through standard app store channels. Therefore, users can install them easily.

Organizations should verify that managed devices run updated versions. Furthermore, administrators should use mobile device management tools when possible. This approach helps ensure all devices receive critical fixes quickly.

Remaining Risks After Patching

The patch blocks future abuse of the flaw. However, it may not invalidate previously stolen tokens. Long-lived authentication tokens can remain active after updates.

Therefore, organizations should take extra precautions. Security teams should review devices that used older versions. In addition, they should revoke existing refresh tokens when necessary. This step forces users to sign in again securely.

For example, businesses with sensitive information should prioritize token reviews. Therefore, they can reduce the risk of unauthorized access. Regular monitoring also helps identify suspicious account activity.

How to Prevent Similar Security Risks

Organizations should keep mobile applications updated at all times. In addition, continuous vulnerability management helps identify weaknesses before attackers exploit them. Managed detection and response services can also monitor devices for unusual activity. Therefore, security teams can quickly detect suspicious applications and account misuse. Regular security assessments and strong mobile device management policies further reduce the risk of token theft and unauthorized access.

Sleep well, we got you covered.

Scroll to Top