A development flag accidentally left active in several Microsoft 365 Android applications allowed unauthorized apps to bypass security checks and harvest account access tokens. This vulnerability, dubbed FlagLeft, originated from a single line of code in a shared software development kit that disabled identity verification for cross-app...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!