Microsoft disclosed a severe intent redirection vulnerability in EngageLab’s third-party Android EngageSDK that could allow a malicious app on the same device to bypass Android sandbox protections and access sensitive data from affected apps. The flaw was tied to an exported activity, MTCommonActivity, which was introduced through the SDK into an app’s merged manifest and could process attacker-controlled intent URIs, causing intents to launch with the vulnerable app’s identity and permissions. Microsoft said the exposure was especially serious for cryptocurrency and digital wallet apps, with affected wallet applications alone accounting for more than 30 million installations.
Microsoft identified the issue in EngageSDK version 4.5.4, reported it to EngageLab in April 2025, and escalated it to the Android Security Team in May 2025. EngageLab fixed the vulnerability in version 5.2.1, released on November 3, 2025, while Google Play removed detected apps using vulnerable SDK versions and Android added automatic protections to mitigate the specific risk as developers update. Microsoft said it found no evidence of in-the-wild exploitation, but warned that insecure third-party mobile SDKs can create broad supply-chain exposure affecting more than 50 million app installations overall.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly disclosed the vulnerability and said affected wallet apps alone accounted for more than 30 million installations, with total exposure across wallet and non-wallet apps exceeding 50 million. Microsoft said it had found no evidence of in-the-wild exploitation at the time of disclosure.
Apps detected as using vulnerable EngageLab SDK versions were removed from Google Play as part of mitigation efforts. Android also added automatic user protections to reduce risk from the specific EngageSDK issue while developers update their apps.
EngageLab fixed the vulnerability in EngageSDK version 5.2.1, released on November 3, 2025. The patch addressed the intent redirection issue that had exposed apps using vulnerable SDK versions to potential data access by malicious local apps.
Microsoft escalated the EngageLab SDK vulnerability to the Android Security Team in May 2025. The issue involved an exported activity, MTCommonActivity, that could process attacker-controlled intent URIs and launch intents with the vulnerable app's identity and permissions.
Microsoft notified EngageLab about the vulnerability in April 2025 after finding the issue in EngageSDK version 4.5.4. The bug affected a widely used SDK embedded in Android apps, including cryptocurrency and digital wallet applications.
Microsoft Defender Security Research identified a severe intent redirection vulnerability in the third-party Android EngageLab EngageSDK, affecting apps that integrated the SDK. The flaw could let a malicious app on the same device bypass Android sandbox protections and access sensitive data from vulnerable apps.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcetechrepublic.com
Open sourcethehackernews.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.