Microsoft Left the Gate Open (Again): Any App Could Steal Your Flock's Credentials

Microsoft Left the Gate Open (Again): Any App Could Steal Your Flock's Credentials

I want you to understand something before I begin. In 1994, I maintained a critical authentication system on magnetic tape backups with a hand-labeled index card catalog. We did not leave debug flags running in production. We did not leave anything running that was not supposed to be running. You checked. You double-checked. Then a colleague checked. Then you went home and worried about it anyway.

Microsoft, apparently, did not get that memo.

Here is what happened. Several Microsoft 365 Android applications shipped with a development flag left switched on in the production build. That flag disabled the trust verification that restricts account token sharing to approved Microsoft applications only. The result: any application sitting on the same device could simply ask for the signed-in user's authentication token and receive it. No password. No login prompt. No friction whatsoever.

Your email. Your calendar. Your files. Handed over like free grain at a county fair. The wolves did not even need a disguise.

This is not sophisticated tradecraft. This is a barn door left open because someone forgot to close it before going home for the weekend. The flock wandered out on their own.

I will note, with considerable irritation, that this is precisely the kind of failure that dial-up era discipline was designed to prevent. When your deployment pipeline takes forty-five minutes over a 28.8k modem, you review your checklist. Modern automated build systems apparently move too fast to notice that a debug configuration is quietly dismantling your entire authentication boundary. Impressive, in a catastrophic sort of way.

The Shepherds in your organization, naturally, will not understand any of this. Brief them using the word "catastrophic" and a chart with a red arrow. That usually works.

Remediation

Right. Here is what you actually do.

Update immediately. Microsoft has issued patched versions of the affected applications. Push them to every Android device in your environment before the end of business today. Not tomorrow. Today.

Audit your mobile application management policy. If you are not controlling which applications can be installed alongside your corporate tools, you are operating a Sky Pasture with no Electric Fence. Fix that.

Review your token issuance logs. If any application outside the expected Microsoft ecosystem requested tokens during the vulnerable window, treat it as a confirmed compromise and rotate credentials for those accounts.

Restrict sideloading. If your Flock can install arbitrary applications from outside the official store, you have already lost the perimeter argument. Lock it down.

Pressure your vendors. A production debug flag is not a vulnerability. It is a process failure. Demand a post-incident report and read it with deep suspicion.

Stay paranoid out there, the wolves certainly are.


Original Report: https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html