A coding mistake in several Microsoft 365 Android applications resulted in the exposure of user accounts to compromise at massive scale, demonstrating once again how dropping the ball on securing authentication tokens can undermine an entire trust model. Researchers at Enclave discovered a vulnerability in a debug setting that was mistakenly left enabled in production releases of multiple Microsoft Android apps, including Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, according to a blog post published Tuesday. "A test setting was left turned on in six Microsoft apps on Android phones: Word, OneNote, PowerPoint, Excel, Loop and 365 Copilot," Enclave co-founder and chief product officer Yanir Tsarimi explains to Dark Reading. "That setting was meant to stop other apps from grabbing your login." The setting's disengagement effectively disabled a security control responsible for ensuring that only trusted Microsoft applications could receive authentication tokens from other Microsoft apps on the device. This feature allows users to log in across the apps, which makes sense if there is a secure handoff in the trust relationship of these apps. According to Enclave, not only was the necessary authorization check protecting this exchange of data disabled in the Android apps, but the access to data also could be replicated across multiple Microsoft apps because the vulnerable code was inside a shared Microsoft software development kit (SDK). With the protection by...
Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover
Dark Reading
·Elizabeth Montalbano
·Published Jun 3, 2026
·Updated
Affected Software
7 affected components
Microsoft Excel
Microsoft Word
Microsoft PowerPoint
Microsoft OneNote
Microsoft Loop
Microsoft Microsoft 365 Copilot
Microsoft shared SDK
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a coding mistake in Microsoft 365 Android applications that exposed user accounts to potential takeover.
2
What security implications are discussed?
The article highlights how the mishandling of authentication tokens can lead to widespread account compromises and weaken trust models.
3
What products or software are affected?
The affected products include Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Microsoft OneNote, Microsoft Loop, and Microsoft 365 Copilot.
4
Who discovered the vulnerability in Microsoft 365?
The vulnerability was discovered by researchers at Enclave.
5
When was the article published?
The article was published on June 3, 2026.