Threat reportVulnerabilityTL-2026-0671
FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token Leak (CVE-2026-41100/41101/41102)
FlagLeft — Microsoft 365 Android Apps Silent Account (TL-2026-0671), also tracked as FlagLeft, is a high-severity software vulnerability, first published 2026-06-03. It has no confirmed attribution, affects Microsoft Word for Android (com.microsoft.office.word), references 3 CVEs (CVE-2026-41100, CVE-2026-41101, CVE-2026-41102), maps to 11 MITRE ATT&CK techniques (T1418, T1428, T1437), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-0671
- Threat ID
- TL-2026-0671
- Also known as
- FlagLeft, setIsDebugMode FOCI token leak, Microsoft 365 Android FOCI token leak
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, education, enterprise, consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 13
How FlagLeft — Microsoft 365 Android Apps Silent Account works
A leftover debug flag — setIsDebugMode(true) — shipped in production builds of the shared Microsoft authentication/broker SDK used by six Microsoft 365 Android apps. With debug mode enabled, the broker skipped the trust check that should verify a requesting app's signing certificate before releasing Family-of-Client-IDs (FOCI) tokens, letting any co-installed Android app silently obtain Microsoft account tokens with no user prompt or consent. The long-lived, refreshable FOCI tokens granted persistent access to mail, files, documents, communications, and calendar data. Affected Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote for Android; Microsoft Teams was not affected. Discovered by Enclave; Microsoft patched via Patch Tuesday and Google Play on 2026-05-12.
FlagLeft is an improper-access-control / token-leak vulnerability rooted in a single line of leftover debug code. Microsoft 365 Android apps share a common authentication SDK (Microsoft Authentication Library family) that implements cross-app single sign-on through an on-device account broker. By design, a 'family' of trusted first-party Microsoft apps can pass OAuth access tokens between one another without re-prompting the user — this is the Family-of-Client-IDs (FOCI) mechanism, in which apps share a Family Refresh Token (FRT) that can be redeemed for per-resource access tokens. To keep this safe, the broker is supposed to verify that any app requesting a token is itself a trusted Microsoft application, by validating the calling package's signing certificate against an allowlist before honoring the request.
The vulnerability is that the shipped production builds of six apps left the SDK configured with setIsDebugMode(true). Enclave found that 'with debug mode enabled, the protection that should have blocked untrusted apps from receiving tokens was skipped.' The debug flag removed the restriction that limited token sharing to other Microsoft apps, causing the broker to 'hand tokens to any Android app that requested them.' The same flag was correctly disabled in other Microsoft apps such as Teams, which is why Teams was not affected.
Exploitation required no exploit chain in the traditional sense — only a co-installed app. Per Enclave's Yanir Tsarimi, an attacker needed roughly 15 lines of code in a malicious Android application: 'It just seeks access to the MS app and is given the token.' The malicious app issues an ordinary broker/account request to a vulnerable Microsoft 365 app; because the debug-mode broker no longer enforces the caller-signature trust check, it returns a valid FOCI token to the untrusted caller with no user prompt and no consent dialog. The attack works fully on-device against any victim who has at least one affected Microsoft 365 app installed and signed in.
The stolen credentials are Microsoft FOCI tokens that, in Enclave's words, could be 'reused and refreshed over long periods without anyone noticing.' Because the family refresh token can be exchanged for fresh access tokens across the family scope, a single silent theft yields durable, self-renewing access. With those tokens an attacker could read emails, files, documents, communications, and calendar information, modify documents, or send communications on behalf of the victim through Microsoft Graph and related cloud APIs.
Microsoft classified the flaws as Spoofing arising from Improper Access Control and rated them Important. Three CVEs were assigned on 2026-05-12: CVE-2026-41100 (Microsoft 365 Copilot for Android), CVE-2026-41101 (Word for Android), and CVE-2026-41102 (PowerPoint for Android, explicitly improper access control); Excel, Loop, and OneNote for Android shared the same root cause. Microsoft did not publish a CVSS vector or score for these CVEs. Fixes were delivered through the May 2026 Patch Tuesday cycle and the Google Play Store (the affected components are mobile apps updated via Play, not OS security updates). No in-the-wild exploitation and no IOCs were published; this is a coordinated vulnerability disclosure. The principal residual risk is the auto-update lag window in which billions of cumulative installs may run unpatched builds.
MITRE ATT&CK techniques used in TL-2026-0671
Discovery
Lateral Movement
T1428 Exploitation of Remote Services
Command and Control
T1437 Application Layer Protocol
Collection
T1533 Data from Local System; T1636 Protected User Data
Execution
Defense Evasion
Credential Access
T1635 Steal Application Access Token
Exfiltration
T1646 Exfiltration Over C2 Channel
Initial Access
Affected products and versions in FlagLeft — Microsoft 365 Android Apps Silent Account
- Microsoft — Word for Android (com.microsoft.office.word)
Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
Fixed in: Google Play build released 2026-05-12 - Microsoft — PowerPoint for Android (com.microsoft.office.powerpoint)
Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
Fixed in: Google Play build released 2026-05-12 - Microsoft — Excel for Android (com.microsoft.office.excel)
Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
Fixed in: Google Play build released 2026-05-12 - Microsoft — Microsoft 365 Copilot for Android (com.microsoft.copilot)
Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
Fixed in: Google Play build released 2026-05-12 - Microsoft — Microsoft Loop for Android (com.microsoft.loop)
Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
Fixed in: Google Play build released 2026-05-12 - Microsoft — OneNote for Android (com.microsoft.office.onenote)
Vulnerable versions: Google Play builds prior to 2026-05-12 fixed release
Fixed in: Google Play build released 2026-05-12 - Microsoft — Microsoft Teams for Android
Fixed in: Not affected — debug flag was disabled
Remediation for FlagLeft — Microsoft 365 Android Apps Silent Account
Patches
- CVE-2026-41100 — Microsoft 365 Copilot for Android: update via Google Play (fixed build 2026-05-12)
- CVE-2026-41101 — Word for Android: update via Google Play (fixed build 2026-05-12)
- CVE-2026-41102 — PowerPoint for Android: update via Google Play (fixed build 2026-05-12)
- Excel, Microsoft Loop, and OneNote for Android: update to latest Google Play builds (same shared-SDK fix, 2026-05-12)
Immediate actions
- Update Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote for Android to the latest Google Play Store builds released on or after 2026-05-12
- Via MDM/Intune, enforce a minimum app version for all six affected Microsoft 365 Android apps and block older builds
- Audit Microsoft 365 sign-in/refresh-token activity for affected users for anomalous or long-lived token reuse and revoke suspicious sessions
Workarounds
- Until apps are confirmed updated, sign out of affected Microsoft 365 Android apps to clear cached broker tokens
- Remove untrusted/sideloaded apps from devices that hold Microsoft 365 sessions
- Use Conditional Access to restrict Microsoft 365 mobile access to compliant devices only
Longer-term hardening
- Enforce Conditional Access and Intune App Protection (MAM) policies that bind Microsoft 365 access on Android to managed, compliant app instances
- Require periodic token re-authentication and shorten refresh-token lifetimes/conditional-access session controls for mobile
- Establish a mobile app inventory and patch-SLA program so Play Store security updates for first-party apps are verified as applied
- Educate users against sideloading apps and granting broad permissions to untrusted Android apps that could request broker tokens
CVEs associated with FlagLeft — Microsoft 365 Android Apps Silent Account
CVE-2026-41100, CVE-2026-41101, CVE-2026-41102
Weaknesses (CWE) in FlagLeft — Microsoft 365 Android Apps Silent Account
Timeline of FlagLeft — Microsoft 365 Android Apps Silent Account
- CVE-2026-41100 (M365 Copilot), CVE-2026-41101 (Word), and CVE-2026-41102 (PowerPoint) published in the MSRC update guide; rated Important, classified Spoofing / Improper Access Control. No CVSS vector published.
- Microsoft shipped fixes through the May 2026 Patch Tuesday cycle and the Google Play Store for the six affected Microsoft 365 Android apps.
- Enclave privately disclosed the leftover setIsDebugMode(true) FOCI token-leak flaw to Microsoft under coordinated disclosure (exact report date not publicly stated; pre-dates the fix).
- SecurityWeek published an exclusive technical write-up; Enclave's Yanir Tsarimi detailed the ~15-line malicious-app exploit and FOCI token reuse.
- Threadlinqs Intelligence ingested and analyzed the disclosure; mapped Mobile ATT&CK techniques and built detection/simulation tasking.
Sources cited for FlagLeft — Microsoft 365 Android Apps Silent Account
- Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
- CVE-2026-41100 — Microsoft Security Response Center advisory (Microsoft 365 Copilot for Android)
- CVE-2026-41101 — Microsoft Security Response Center advisory (Word for Android)
- CVE-2026-41102 — Microsoft Security Response Center advisory (PowerPoint for Android)
- CVE-2026-41101 Spoofing Flaw in Word for Android — patch guide
- CVE-2026-41102 — Microsoft Fixes Spoofing/Improper-Access-Control in PowerPoint for Android
- MITRE ATT&CK for Mobile — T1635 Steal Application Access Token
Detection coverage for TL-2026-0671
As of 2026-06-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0671 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.