Microsoft is warning of a worrying security breach that exposed more than 50 million Android users, saying “user credentials and financial data were at risk.”


  • Microsoft discovered a flaw in the EngageLab SDK affecting 50 million Android devices
  • Vulnerability allows apps to bypass sandbox and access private data
  • At least 30 million installs were crypto apps, fixed in version 5.2.1

According to experts, around 50 million Android devices were running apps with vulnerabilities that allowed malicious actors to access private data stored on these devices. Many of these installs were cryptocurrency apps, which only made the problem worse.

Microsoft security researchers said they have identified an “intent redirection vulnerability” in EngageLab SDK, a popular software development kit that helps build user engagement features such as push notifications or in-app messaging.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top