CVE-2026-41101
CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21º percentile). Patch Microsoft: Release Notes.
Vulnerabilità ed exploit · Furto di credenziali
Un bug dell’app corretto non mette automaticamente fine all’accesso che aveva già concesso. In queste app Microsoft 365 per Android, un’app malevola poteva ancora restare su un telefono come punto d’appoggio permanente dell’account perché i refresh token FOCI condivisi rimangono validi dopo l’update finché non vengono revocati.
2 fonti · 3 giu
CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21º percentile). Patch Microsoft: Release Notes.
CVSS 4.4 MEDIUM: improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. EPSS 0.3% (15º percentile). Patch Microsoft: Release Notes.
The Hacker News
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
Debug flag disabled Microsoft 365 Android token checks, letting untrusted apps access accounts; patches issued May 12 to reduce risk
originaleSecurityWeek
Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-03
Every edition of this story: Le app Microsoft Android patchate possono ancora esporre l’accesso