
Microsoft 365の各Androidアプリに他の任意のアプリからアカウントトークンを窃取可能な脆弱性"FlagLeft"。デバッグフラグの消し忘れ。5月の定例でCVE-2026-41100、CVE-2026-41101、CVE-2026-41102、CVE-2026-42832として修正済み。 https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html
Post summary
A debug‑flag issue in Microsoft 365 Android apps (FlagLeft) allowed token theft, which was promptly patched in May with several CVE IDs.

