Microsoft warns of troubling security flaw exposed to over 50 million Android users, says ‘user information and financial data were exposed’


  • Microsoft found EngageLab SDK flaw affecting 50 million Android devices
  • Vulnerability lets apps bypass sandboxing and access private data
  • At least 30 million installs were crypto apps, patched in v5.2.1

About 50 million Android devices used apps with vulnerabilities that allowed threat actors to access private data stored on those devices, experts have warned. Many of these installations were cryptocurrency apps, which only added to the problem.

Security researchers from Microsoft said they identified an “intent redirection vulnerability” in the EngageLab SDK, a popular software development kit that helps build user engagement features such as push notifications or in-app notifications.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top