Microsoft warns that a worrying security flaw exposed more than 50 million Android users and says that “user credentials and financial data were exposed to risks”



  • Microsoft found a flaw in the EngageLab SDK affecting 50 million Android devices
  • Vulnerability allows applications to bypass sandbox and access private data
  • At least 30 million installs were crypto apps, patched in v5.2.1

Approximately 50 million Android devices were running apps with vulnerabilities that allowed threat actors to access private data stored on those devices, experts warned. Many of those installations were cryptocurrency apps, which only exacerbated the problem.

Microsoft security researchers said they identified an “intent redirection vulnerability” in EngageLab SDK, a popular software development kit that helps create user engagement features such as push notifications or in-app messages.



Leave a Comment

Your email address will not be published. Required fields are marked *