CVE-2026-41101
CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21st percentile). Microsoft patch: Release Notes.
Vulnerabilities · 103 days ago
A fixed app bug does not automatically end the access it already handed out. On these Microsoft 365 Android apps, a malicious app could still sit on a phone as a standing account foothold because the shared FOCI refresh tokens remain valid after the update until they are revoked.
The flaw was a leftover debug flag in Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote for Android. It skipped the trust check that should have limited token handoff to Microsoft apps, so any other app on the device could obtain the signed-in user’s token with no password prompt or permission screen. Microsoft patched the apps on May 12, but the issue spans four CVEs and affects the shared Microsoft 365 account layer across those apps, not just one install.
That changes the standard response. Updating removes the bad build, but it does not necessarily remove the token an attacker already captured, so mail, files, calendars, and messages can stay exposed until those refresh tokens are revoked.
CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21st percentile). Microsoft patch: Release Notes.
CVSS 4.4 MEDIUM: improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. EPSS 0.2% (16th percentile). Microsoft patch: Release Notes.
2 sources covering this story
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
Debug flag disabled Microsoft 365 Android token checks, letting untrusted apps access accounts; patches issued May 12 to reduce risk
Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.
Part of the PlainSec briefing for 2026-06-03