A disabled security setting meant to protect authentication across Android versions of key apps paved the way for attackers to steal logins and data.

SecurityWeek Exclusive: Researchers discovered a debug mode flaw in six Microsoft Android apps that could have enabled exploitation.

Debug flag disabled Microsoft 365 Android token checks, letting untrusted apps access accounts; patches issued May 12 to reduce risk