Threat reportVulnerabilityTL-2026-0671

FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token Leak (CVE-2026-41100/41101/41102)

highACTIVE

FlagLeft — Microsoft 365 Android Apps Silent Account (TL-2026-0671), also tracked as FlagLeft, is a high-severity software vulnerability, first published 2026-06-03. It has no confirmed attribution, affects Microsoft Word for Android (com.microsoft.office.word), references 3 CVEs (CVE-2026-41100, CVE-2026-41101, CVE-2026-41102), maps to 11 MITRE ATT&CK techniques (T1418, T1428, T1437), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
3Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-0671

Threat ID
TL-2026-0671
Also known as
FlagLeft, setIsDebugMode FOCI token leak, Microsoft 365 Android FOCI token leak
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, technology, education, enterprise, consumer
Target regions
Global
Detection rules
9
Indicators of compromise
13

How FlagLeft — Microsoft 365 Android Apps Silent Account works

A leftover debug flag — setIsDebugMode(true) — shipped in production builds of the shared Microsoft authentication/broker SDK used by six Microsoft 365 Android apps. With debug mode enabled, the broker skipped the trust check that should verify a requesting app's signing certificate before releasing Family-of-Client-IDs (FOCI) tokens, letting any co-installed Android app silently obtain Microsoft account tokens with no user prompt or consent. The long-lived, refreshable FOCI tokens granted persistent access to mail, files, documents, communications, and calendar data. Affected Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote for Android; Microsoft Teams was not affected. Discovered by Enclave; Microsoft patched via Patch Tuesday and Google Play on 2026-05-12.

FlagLeft is an improper-access-control / token-leak vulnerability rooted in a single line of leftover debug code. Microsoft 365 Android apps share a common authentication SDK (Microsoft Authentication Library family) that implements cross-app single sign-on through an on-device account broker. By design, a 'family' of trusted first-party Microsoft apps can pass OAuth access tokens between one another without re-prompting the user — this is the Family-of-Client-IDs (FOCI) mechanism, in which apps share a Family Refresh Token (FRT) that can be redeemed for per-resource access tokens. To keep this safe, the broker is supposed to verify that any app requesting a token is itself a trusted Microsoft application, by validating the calling package's signing certificate against an allowlist before honoring the request.

The vulnerability is that the shipped production builds of six apps left the SDK configured with setIsDebugMode(true). Enclave found that 'with debug mode enabled, the protection that should have blocked untrusted apps from receiving tokens was skipped.' The debug flag removed the restriction that limited token sharing to other Microsoft apps, causing the broker to 'hand tokens to any Android app that requested them.' The same flag was correctly disabled in other Microsoft apps such as Teams, which is why Teams was not affected.

Exploitation required no exploit chain in the traditional sense — only a co-installed app. Per Enclave's Yanir Tsarimi, an attacker needed roughly 15 lines of code in a malicious Android application: 'It just seeks access to the MS app and is given the token.' The malicious app issues an ordinary broker/account request to a vulnerable Microsoft 365 app; because the debug-mode broker no longer enforces the caller-signature trust check, it returns a valid FOCI token to the untrusted caller with no user prompt and no consent dialog. The attack works fully on-device against any victim who has at least one affected Microsoft 365 app installed and signed in.

The stolen credentials are Microsoft FOCI tokens that, in Enclave's words, could be 'reused and refreshed over long periods without anyone noticing.' Because the family refresh token can be exchanged for fresh access tokens across the family scope, a single silent theft yields durable, self-renewing access. With those tokens an attacker could read emails, files, documents, communications, and calendar information, modify documents, or send communications on behalf of the victim through Microsoft Graph and related cloud APIs.

Microsoft classified the flaws as Spoofing arising from Improper Access Control and rated them Important. Three CVEs were assigned on 2026-05-12: CVE-2026-41100 (Microsoft 365 Copilot for Android), CVE-2026-41101 (Word for Android), and CVE-2026-41102 (PowerPoint for Android, explicitly improper access control); Excel, Loop, and OneNote for Android shared the same root cause. Microsoft did not publish a CVSS vector or score for these CVEs. Fixes were delivered through the May 2026 Patch Tuesday cycle and the Google Play Store (the affected components are mobile apps updated via Play, not OS security updates). No in-the-wild exploitation and no IOCs were published; this is a coordinated vulnerability disclosure. The principal residual risk is the auto-update lag window in which billions of cumulative installs may run unpatched builds.

MITRE ATT&CK techniques used in TL-2026-0671

Discovery

T1418 Software Discovery

Lateral Movement

T1428 Exploitation of Remote Services

Command and Control

T1437 Application Layer Protocol

Collection

T1533 Data from Local System; T1636 Protected User Data

Execution

T1575 Native API

Defense Evasion

T1628 Hide Artifacts

Credential Access

T1635 Steal Application Access Token

Exfiltration

T1646 Exfiltration Over C2 Channel

Initial Access

T1660 Phishing; T1661 Application Versioning

Affected products and versions in FlagLeft — Microsoft 365 Android Apps Silent Account

  • Microsoft — Word for Android (com.microsoft.office.word)
    Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
    Fixed in: Google Play build released 2026-05-12
  • Microsoft — PowerPoint for Android (com.microsoft.office.powerpoint)
    Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
    Fixed in: Google Play build released 2026-05-12
  • Microsoft — Excel for Android (com.microsoft.office.excel)
    Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
    Fixed in: Google Play build released 2026-05-12
  • Microsoft — Microsoft 365 Copilot for Android (com.microsoft.copilot)
    Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
    Fixed in: Google Play build released 2026-05-12
  • Microsoft — Microsoft Loop for Android (com.microsoft.loop)
    Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
    Fixed in: Google Play build released 2026-05-12
  • Microsoft — OneNote for Android (com.microsoft.office.onenote)
    Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
    Fixed in: Google Play build released 2026-05-12
  • Microsoft — Microsoft Teams for Android
    Fixed in: Not affected — debug flag was disabled

Remediation for FlagLeft — Microsoft 365 Android Apps Silent Account

Patches

  • CVE-2026-41100 — Microsoft 365 Copilot for Android: update via Google Play (fixed build 2026-05-12)
  • CVE-2026-41101 — Word for Android: update via Google Play (fixed build 2026-05-12)
  • CVE-2026-41102 — PowerPoint for Android: update via Google Play (fixed build 2026-05-12)
  • Excel, Microsoft Loop, and OneNote for Android: update to latest Google Play builds (same shared-SDK fix, 2026-05-12)

Immediate actions

  • Update Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote for Android to the latest Google Play Store builds released on or after 2026-05-12
  • Via MDM/Intune, enforce a minimum app version for all six affected Microsoft 365 Android apps and block older builds
  • Audit Microsoft 365 sign-in/refresh-token activity for affected users for anomalous or long-lived token reuse and revoke suspicious sessions

Workarounds

  • Until apps are confirmed updated, sign out of affected Microsoft 365 Android apps to clear cached broker tokens
  • Remove untrusted/sideloaded apps from devices that hold Microsoft 365 sessions
  • Use Conditional Access to restrict Microsoft 365 mobile access to compliant devices only

Longer-term hardening

  • Enforce Conditional Access and Intune App Protection (MAM) policies that bind Microsoft 365 access on Android to managed, compliant app instances
  • Require periodic token re-authentication and shorten refresh-token lifetimes/conditional-access session controls for mobile
  • Establish a mobile app inventory and patch-SLA program so Play Store security updates for first-party apps are verified as applied
  • Educate users against sideloading apps and granting broad permissions to untrusted Android apps that could request broker tokens

CVEs associated with FlagLeft — Microsoft 365 Android Apps Silent Account

CVE-2026-41100, CVE-2026-41101, CVE-2026-41102

Weaknesses (CWE) in FlagLeft — Microsoft 365 Android Apps Silent Account

CWE-489, CWE-284, CWE-863, CWE-522, CWE-295

Timeline of FlagLeft — Microsoft 365 Android Apps Silent Account

  • CVE-2026-41100 (M365 Copilot), CVE-2026-41101 (Word), and CVE-2026-41102 (PowerPoint) published in the MSRC update guide; rated Important, classified Spoofing / Improper Access Control. No CVSS vector published.
  • Microsoft shipped fixes through the May 2026 Patch Tuesday cycle and the Google Play Store for the six affected Microsoft 365 Android apps.
  • Enclave privately disclosed the leftover setIsDebugMode(true) FOCI token-leak flaw to Microsoft under coordinated disclosure (exact report date not publicly stated; pre-dates the fix).
  • SecurityWeek published an exclusive technical write-up; Enclave's Yanir Tsarimi detailed the ~15-line malicious-app exploit and FOCI token reuse.
  • Threadlinqs Intelligence ingested and analyzed the disclosure; mapped Mobile ATT&CK techniques and built detection/simulation tasking.

Sources cited for FlagLeft — Microsoft 365 Android Apps Silent Account

Detection coverage for TL-2026-0671

As of 2026-06-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0671 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats