• News/
  • darkreading-20260603190041

Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover

Dark Reading
·
Elizabeth Montalbano
·
Published Jun 3, 2026
·
Updated

A coding mistake in several Microsoft 365 Android applications resulted in the exposure of user accounts to compromise at massive scale, demonstrating once again how dropping the ball on securing authentication tokens can undermine an entire trust model. Researchers at Enclave discovered a vulnerability in a debug setting that was mistakenly left enabled in production releases of multiple Microsoft Android apps, including Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, according to a blog post published Tuesday. "A test setting was left turned on in six Microsoft apps on Android phones: Word, OneNote, PowerPoint, Excel, Loop and 365 Copilot," Enclave co-founder and chief product officer Yanir Tsarimi explains to Dark Reading. "That setting was meant to stop other apps from grabbing your login." The setting's disengagement effectively disabled a security control responsible for ensuring that only trusted Microsoft applications could receive authentication tokens from other Microsoft apps on the device. This feature allows users to log in across the apps, which makes sense if there is a secure handoff in the trust relationship of these apps. According to Enclave, not only was the necessary authorization check protecting this exchange of data disabled in the Android apps, but the access to data also could be replicated across multiple Microsoft apps because the vulnerable code was inside a shared Microsoft software development kit (SDK). With the protection by...

Read full article

Affected Software

7 affected components
Microsoft Excel
Microsoft Word
Microsoft PowerPoint
Microsoft OneNote
Microsoft Loop
Microsoft Microsoft 365 Copilot
Microsoft shared SDK
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a coding mistake in Microsoft 365 Android applications that exposed user accounts to potential takeover.

2

What security implications are discussed?

The article highlights how the mishandling of authentication tokens can lead to widespread account compromises and weaken trust models.

3

What products or software are affected?

The affected products include Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Microsoft OneNote, Microsoft Loop, and Microsoft 365 Copilot.

4

Who discovered the vulnerability in Microsoft 365?

The vulnerability was discovered by researchers at Enclave.

5

When was the article published?

The article was published on June 3, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203