Microsoft 365 Android Apps Patched After FlagLeft Token Vulnerability
Microsoft has patched a serious Android security flaw that allowed a rogue app on the same device to request Microsoft account tokens from several Microsoft 365 apps. The issue, dubbed FlagLeft by Enclave, affected Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote for Android.
The vulnerability came from a development flag left active in production builds. According to researchers, the setting changed how Microsoft 365 Android apps handled token-sharing requests and allowed an untrusted app to receive tokens without a login prompt, Android permission request, or visible warning to the user.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The practical risk was account takeover through token access. A malicious app already installed on the same Android phone could potentially use exposed tokens to act as the signed-in user, read emails, open files, access documents, send messages, or view calendar information.
What Microsoft 365 Android apps were affected?
Researchers confirmed the issue across six Microsoft apps on Android. Teams was not listed among the affected apps because its debug setting was reportedly disabled correctly in production.
| App | Status reported by researchers | Public CVE coverage |
|---|---|---|
| Microsoft 365 Copilot for Android | Affected and patched | CVE-2026-41100 |
| Word for Android | Affected and patched | CVE-2026-41101 |
| PowerPoint for Android | Affected and patched | CVE-2026-41102 |
| Excel for Android | Affected and patched | CVE-2026-42832 |
| Microsoft Loop for Android | Affected and patched | No separate CVE listed in the same public batch |
| OneNote for Android | Affected and patched | No separate CVE listed in the same public batch |
The issue did not require the attacker to steal a password first. The malicious app only needed to run on the same Android device and make the right token request to an affected Microsoft app.
How the FlagLeft flaw worked
Microsoft 365 apps use token sharing to make sign-in smoother across the app family. If a user signs in to Word, other Microsoft apps can avoid asking the same user to sign in again. This single sign-on flow depends on a trust check that should confirm which app asks for the token.
The flaw came from the debug setting setIsDebugMode(true). Enclave said the setting appeared in production across the affected apps and disabled the authorization check that should have blocked non-Microsoft apps from receiving tokens.
The same pattern appeared across several apps because the vulnerable code sat inside a shared Microsoft SDK. Enclaveโs technical write-up said researchers first found the issue in one app, then used variant analysis to confirm the same behavior elsewhere in the Microsoft 365 Android portfolio.
Why token access created a serious risk
The exposed tokens were FOCI tokens, short for Family of Client IDs. Microsoft uses this mechanism to let related apps share authentication across a trusted app family. The problem was not the token-sharing design itself, but the disabled trust gate that allowed an untrusted app into that flow.
Once a rogue app received valid tokens, its activity could look like normal Microsoft 365 traffic. That made the issue harder for users to notice, especially because the exploit did not need a fake login page or a permission request.
The public records for Microsoft 365 Copilot and Word for Android describe the issue as improper access control that could allow local spoofing. Both were published on May 12, 2026.
The records for PowerPoint for Android and Microsoft Office also point to improper access control. Excel was covered under the Microsoft Office spoofing vulnerability and received a higher CVSS score than the Copilot, Word, and PowerPoint entries.
Severity and patch status
| CVE | Product | Issue type | CVSS score |
|---|---|---|---|
| CVE-2026-41100 | Microsoft 365 Copilot for Android | Spoofing through improper access control | 4.4 Medium |
| CVE-2026-41101 | Word for Android | Spoofing through improper access control | 7.1 High |
| CVE-2026-41102 | PowerPoint for Android | Spoofing through improper access control | 7.1 High |
| CVE-2026-42832 | Microsoft Office, including Excel for Android | Spoofing through improper access control | 7.7 High or Important, depending on source display |
Microsoft confirmed and fixed the reported issues through its normal security process. Users should update Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote on Android from Google Play or through their companyโs mobile device management system.
Enterprise administrators should confirm that managed devices no longer run vulnerable builds. They should also review risky devices that had older Microsoft 365 Android apps installed alongside unknown or untrusted apps.
What users and IT admins should do
The fix closes the vulnerable path, but updating alone may not remove risk if a malicious app already received tokens before the patch. In higher-risk cases, organizations should consider forcing affected users to sign in again and reviewing account activity for unusual access.
- Update all Microsoft 365 Android apps from Google Play or managed app stores.
- Check Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote on managed Android devices.
- Remove unknown Android apps from devices used for work accounts.
- Force reauthentication for users whose devices ran vulnerable builds with untrusted apps installed.
- Review Microsoft 365 sign-in and session activity for unusual access patterns.
- Use mobile device management policies to block outdated app versions where possible.
For consumers, the most important step is simple: update the affected apps and uninstall Android apps from unknown developers. Users who opened suspicious files, installed unknown APKs, or used unofficial app stores should treat the device as higher risk.
FlagLeft shows how a small development mistake can weaken a large authentication system when shared code reaches multiple production apps. The case also highlights why mobile token handling needs strict release checks, especially in apps that protect email, documents, calendars, and cloud files.
FAQ
FlagLeft is a vulnerability found in several Microsoft 365 Android apps. Researchers said a debug flag left active in production allowed a rogue app on the same Android device to request Microsoft account tokens from affected Microsoft apps.
Researchers confirmed the issue in Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote for Android. Microsoft Teams was not listed as affected because its debug setting was reportedly disabled in production.
Yes. If a malicious app received valid tokens, it could potentially act as the signed-in Microsoft account within the access allowed by those tokens. That could expose emails, documents, files, calendar data, and communications.
Yes. The reported issues have been patched. Android users should update Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote to the latest available versions.
Users should update the affected Microsoft 365 apps, remove unknown apps, avoid unofficial app stores, and review account activity if they used vulnerable app versions on a device with untrusted apps installed.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages