Microsoft warns worrying security flaw exposed over 50 million Android users, says ‘user credentials and financial data were exposed to risk’



  • Microsoft found EngageLab SDK flaw affecting 50 million Android devices
  • Vulnerability let apps bypass sandbox and access private data
  • At least 30 million installs were crypto apps, patched in v5.2.1

Roughly 50 million Android devices were using apps with vulnerabilities that allowed threat actors to access private data stored on those devices, experts have warned. Many of those installations were cryptocurrency apps, which only made the problem bigger.

Security researchers from Microsoft said they identified an “intent redirection vulnerability” in EngageLab SDK, a popular software development kit that helps build user engagement features such as push notifications or in-app messaging.


https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img