By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Forgotten Debug Flag in Microsoft 365 Android Apps Exposed Account Tokens to Any App
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

Forgotten Debug Flag in Microsoft 365 Android Apps Exposed Account Tokens to Any App

An overlooked debug flag in six Microsoft 365 Android apps allowed any untrusted app on the device to silently steal Microsoft account tokens, bypassing all authorization checks.

CSBadmin
Last updated: June 3, 2026 11:02 am
CSBadmin
2 Min Read
Share
SHARE

The Root Cause: A Debugging Oversight

A single line of debug code left enabled in production builds of six Microsoft 365 Android apps silently handed over user account tokens to any third-party app on the same device, without any notification or consent. Security researchers discovered that the flag `setIsDebugMode(true)` remained active in the shared Microsoft SDK used by Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and Microsoft OneNote. This flag turned off the authorization check that normally restricts token requests to trusted Microsoft applications only. Microsoft Teams was not affected because its debug flag was correctly set to false in production.

Contents
The Root Cause: A Debugging OversightHow the Attack Worked and Its Impact

How the Attack Worked and Its Impact

The vulnerability exploited Microsoft’s FOCI (Family of Client IDs) token sharing system, which is designed to enable seamless single sign-on across the Microsoft 365 suite. Normally, FOCI allows legitimate Microsoft apps to request tokens from each other without requiring separate logins. However, with debug mode activated, any co-installed, untrusted third-party app could make the same token request and receive valid, long-lived, refreshable Microsoft account tokens. An attacker could then silently read emails, access OneDrive files, send messages, and view calendar data, all under the identity of the signed-in user, with no suspicious activity appearing in logs. Microsoft has patched all reported issues, assigning severity ratings ranging from medium to high.

Source: Cyber Security News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverAndroidDebug ModeSDK Vulnerability
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article HTTP/2 Attack Chokes Major Web Servers With Memory Exhaustion
Next Article Microsoft Silently Fixes Azure Backup for AKS Privilege Escalation Vulnerability

Trending

StreamRat trojan rides fake TV apps to take over Android devices
September 3, 2026
Signed node.exe is latest cover for malware delivery, Symantec finds
September 3, 2026
Russian man extradited over Excel malware sent to 80,000 freelancers
September 3, 2026
Fake tax and shipping lures push RMM installs across 46 countries
September 3, 2026
Poisoned Git configs make AI coding agents run attacker commands
September 3, 2026

Related Stories

CSBadmin

Kimsuky runs local AI models to sharpen phishing lures

CSBadmin

NASA mission console flaws open spacecraft commands to strangers

CSBadmin

Threat Actor Claims Theft of 35 GB of Source Code from Accenture

CSBadmin

TP-Link Omada chain turns guessed serial numbers into network takeover

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.