Patched Microsoft Android Apps Can Still Leak Access
A fixed app bug does not automatically end the access it already handed out. On these Microsoft 365 Android apps, a malicious app could still sit on a phone as a standing account foothold because the shared FOCI refresh tokens remain valid after the update until they are revoked.
The flaw was a leftover debug flag in Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote for Android. It skipped the trust check that should have limited token handoff to Microsoft apps, so any other app on the device could obtain the signed-in user’s token with no password prompt or permission screen. Microsoft patched the apps on May 12, but the issue spans four CVEs and affects the shared Microsoft 365 account layer across those apps, not just one install.
That changes the standard response. Updating removes the bad build, but it does not necessarily remove the token an attacker already captured, so mail, files, calendars, and messages can stay exposed until those refresh tokens are revoked.