Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Is Anthropic restricting the release of Mythos to protect the internet? Or Anthropic?

EngageLab SDK flaw exposes 50 million Android users, including 30 million crypto wallets

Sierra’s Brett Taylor says the days of clicking buttons are over

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » EngageLab SDK flaw exposes 50 million Android users, including 30 million crypto wallets
Identity

EngageLab SDK flaw exposes 50 million Android users, including 30 million crypto wallets

By April 9, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 9, 2026Vulnerabilities / Mobile Security

Details have emerged of a patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could potentially put millions of cryptocurrency wallet users at risk.

“This flaw allows apps on the same device to bypass the Android security sandbox and gain unauthorized access to private data,” the Microsoft Defender Security Research Team said in a report published today.

The EngageLab SDK provides a push notification service that, according to its website, is designed to deliver “timely notifications” based on user behavior that is already tracked by the developer. Integrating the SDK into your app provides a way to send personalized notifications and drive real-time engagement.

The tech giant said that a significant number of apps that use the SDK are part of the cryptocurrency and digital wallet ecosystem, and that the affected wallet apps account for more than 30 million installs. If you include non-wallet apps built on the same SDK, the number of installs is over 50 million.

Microsoft did not name the apps, but said all detected apps using vulnerable versions of the SDK have been removed from the Google Play Store. Following responsible disclosure in April 2025, EngageLab released version 5.2.1 in November 2025 to address the vulnerability.

This issue was identified in version 4.5.4 and is described as an intent redirection vulnerability. An intent in Android refers to a messaging object used to request an action from another app component.

Intent redirection occurs when the content of an intent sent by a vulnerable app is manipulated by leveraging its trusted context (i.e., permissions) to gain unauthorized access to protected components, expose sensitive data, or escalate privileges within the Android environment.

An attacker could exploit this vulnerability with a malicious app installed on the device through other means to access internal directories associated with the app in which the SDK is integrated, and gain unauthorized access to sensitive data.

There is no evidence that this vulnerability has been exploited in a malicious context. That said, we recommend that developers integrating SDKs update to the latest version as soon as possible, especially considering that even a minor flaw in an upstream library can have a cascading effect that can impact millions of devices.

“This case illustrates how weaknesses in third-party SDKs can have large-scale security implications, especially in high-value areas such as digital asset management,” Microsoft said. “Apps are increasingly reliant on third-party SDKs, creating large and opaque supply chain dependencies. These risks are exacerbated when integrations expose exported components or rely on unverified trust assumptions across app boundaries.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSierra’s Brett Taylor says the days of clicking buttons are over
Next Article Is Anthropic restricting the release of Mythos to protect the internet? Or Anthropic?

Related Posts

UAT-10362 Spear phishing campaign uses LucidRook malware to target NGOs in Taiwan

April 9, 2026

Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

April 9, 2026

The hidden security risks of shadow AI in the enterprise

April 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Is Anthropic restricting the release of Mythos to protect the internet? Or Anthropic?

EngageLab SDK flaw exposes 50 million Android users, including 30 million crypto wallets

Sierra’s Brett Taylor says the days of clicking buttons are over

UAT-10362 Spear phishing campaign uses LucidRook malware to target NGOs in Taiwan

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.