Microsoft 365 Android Apps Token Theft Debug Flag | MSSP Advisory

HighCredible Report
DateJune 3, 2026
📋Executive Summary
A debug flag left set to true in production builds of six Microsoft 365 Android apps disabled the token-sharing trust check, allowing any app on the same device to silently request and receive FOCI refresh tokens for the signed-in Microsoft 365 account. Affected apps include Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote. Microsoft patched the flaw via Google Play updates in May 2026 across four CVEs, but existing refresh tokens on previously exposed devices remain valid until explicitly revoked.
⚠️Why It Matters for MSSPs
If any technician or employee in your shop runs Microsoft 365 apps on an Android device alongside any unvetted app, their account tokens could have been silently harvested before the patch, giving an attacker persistent access to email, files, and calendar with no visible trace. On the client side, your managed Android users running these apps before the update are in the same position, and FOCI tokens that were already pulled are still alive right now regardless of whether the apps are patched.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Identity Access

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.