Microsoft 365 Android Apps Patched After FlagLeft Token Vulnerability


Microsoft has patched a serious Android security flaw that allowed a rogue app on the same device to request Microsoft account tokens from several Microsoft 365 apps. The issue, dubbed FlagLeft by Enclave, affected Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote for Android.

The vulnerability came from a development flag left active in production builds. According to researchers, the setting changed how Microsoft 365 Android apps handled token-sharing requests and allowed an untrusted app to receive tokens without a login prompt, Android permission request, or visible warning to the user.

The practical risk was account takeover through token access. A malicious app already installed on the same Android phone could potentially use exposed tokens to act as the signed-in user, read emails, open files, access documents, send messages, or view calendar information.

What Microsoft 365 Android apps were affected?

Researchers confirmed the issue across six Microsoft apps on Android. Teams was not listed among the affected apps because its debug setting was reportedly disabled correctly in production.

AppStatus reported by researchersPublic CVE coverage
Microsoft 365 Copilot for AndroidAffected and patchedCVE-2026-41100
Word for AndroidAffected and patchedCVE-2026-41101
PowerPoint for AndroidAffected and patchedCVE-2026-41102
Excel for AndroidAffected and patchedCVE-2026-42832
Microsoft Loop for AndroidAffected and patchedNo separate CVE listed in the same public batch
OneNote for AndroidAffected and patchedNo separate CVE listed in the same public batch

The issue did not require the attacker to steal a password first. The malicious app only needed to run on the same Android device and make the right token request to an affected Microsoft app.

How the FlagLeft flaw worked

Microsoft 365 apps use token sharing to make sign-in smoother across the app family. If a user signs in to Word, other Microsoft apps can avoid asking the same user to sign in again. This single sign-on flow depends on a trust check that should confirm which app asks for the token.

The flaw came from the debug setting setIsDebugMode(true). Enclave said the setting appeared in production across the affected apps and disabled the authorization check that should have blocked non-Microsoft apps from receiving tokens.

The same pattern appeared across several apps because the vulnerable code sat inside a shared Microsoft SDK. Enclaveโ€™s technical write-up said researchers first found the issue in one app, then used variant analysis to confirm the same behavior elsewhere in the Microsoft 365 Android portfolio.

Why token access created a serious risk

The exposed tokens were FOCI tokens, short for Family of Client IDs. Microsoft uses this mechanism to let related apps share authentication across a trusted app family. The problem was not the token-sharing design itself, but the disabled trust gate that allowed an untrusted app into that flow.

Once a rogue app received valid tokens, its activity could look like normal Microsoft 365 traffic. That made the issue harder for users to notice, especially because the exploit did not need a fake login page or a permission request.

The public records for Microsoft 365 Copilot and Word for Android describe the issue as improper access control that could allow local spoofing. Both were published on May 12, 2026.

The records for PowerPoint for Android and Microsoft Office also point to improper access control. Excel was covered under the Microsoft Office spoofing vulnerability and received a higher CVSS score than the Copilot, Word, and PowerPoint entries.

Severity and patch status

CVEProductIssue typeCVSS score
CVE-2026-41100Microsoft 365 Copilot for AndroidSpoofing through improper access control4.4 Medium
CVE-2026-41101Word for AndroidSpoofing through improper access control7.1 High
CVE-2026-41102PowerPoint for AndroidSpoofing through improper access control7.1 High
CVE-2026-42832Microsoft Office, including Excel for AndroidSpoofing through improper access control7.7 High or Important, depending on source display

Microsoft confirmed and fixed the reported issues through its normal security process. Users should update Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote on Android from Google Play or through their companyโ€™s mobile device management system.

Enterprise administrators should confirm that managed devices no longer run vulnerable builds. They should also review risky devices that had older Microsoft 365 Android apps installed alongside unknown or untrusted apps.

What users and IT admins should do

The fix closes the vulnerable path, but updating alone may not remove risk if a malicious app already received tokens before the patch. In higher-risk cases, organizations should consider forcing affected users to sign in again and reviewing account activity for unusual access.

  • Update all Microsoft 365 Android apps from Google Play or managed app stores.
  • Check Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote on managed Android devices.
  • Remove unknown Android apps from devices used for work accounts.
  • Force reauthentication for users whose devices ran vulnerable builds with untrusted apps installed.
  • Review Microsoft 365 sign-in and session activity for unusual access patterns.
  • Use mobile device management policies to block outdated app versions where possible.

For consumers, the most important step is simple: update the affected apps and uninstall Android apps from unknown developers. Users who opened suspicious files, installed unknown APKs, or used unofficial app stores should treat the device as higher risk.

FlagLeft shows how a small development mistake can weaken a large authentication system when shared code reaches multiple production apps. The case also highlights why mobile token handling needs strict release checks, especially in apps that protect email, documents, calendars, and cloud files.

FAQ

What is the FlagLeft Microsoft 365 Android vulnerability?

FlagLeft is a vulnerability found in several Microsoft 365 Android apps. Researchers said a debug flag left active in production allowed a rogue app on the same Android device to request Microsoft account tokens from affected Microsoft apps.

Which Microsoft 365 Android apps were affected by FlagLeft?

Researchers confirmed the issue in Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote for Android. Microsoft Teams was not listed as affected because its debug setting was reportedly disabled in production.

Could the Microsoft 365 Android flaw lead to account takeover?

Yes. If a malicious app received valid tokens, it could potentially act as the signed-in Microsoft account within the access allowed by those tokens. That could expose emails, documents, files, calendar data, and communications.

Has Microsoft patched the Microsoft 365 Android vulnerability?

Yes. The reported issues have been patched. Android users should update Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote to the latest available versions.

What should Android users do now?

Users should update the affected Microsoft 365 apps, remove unknown apps, avoid unofficial app stores, and review account activity if they used vulnerable app versions on a device with untrusted apps installed.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages