Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
A debug flag left enabled in production builds of Microsoft 365 Android apps allows any app on the same device to steal account tokens. This bypasses the trusted-app check, letting malicious apps access email, files, calendar, and send messages as the signed-in user without any password or permission prompt.
Any app can steal Microsoft 365 tokens, compromising user data without user interaction.


