Executive brief
A security vulnerability in the Microsoft Office app for Android could allow an attacker to perform spoofing attacks on a user's device. This issue stems from improper access controls within the application. If exploited, an attacker could potentially trick users into performing unintended actions or misrepresenting information within the app, compromising the integrity of user data and interactions.
Technical details
A vulnerability classified as improper access control (CWE-284) exists in Microsoft Office for Android. The flaw allows a local attacker to perform spoofing attacks, potentially leading to unauthorized data modification or information disclosure. Exploitation requires user interaction, as indicated by the CVSS vector (UI:R), meaning a victim must perform a specific action for the attack to succeed. The vulnerability has a CVSS 3.1 base score of 7.1, reflecting high impacts on confidentiality and integrity. Users are advised to update their Office for Android application to the latest version available via the Google Play Store to mitigate this risk.
Affected products
- Microsoft Office Android
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory