Executive brief
Microsoft Teams for Android is a mobile messaging and collaboration application used by millions of enterprise users. An attacker with authorized access to the application could inject malicious code that enables spoofing of messages or identities within Teams conversations, potentially compromising the integrity of communications and enabling social engineering attacks.
Technical details
This vulnerability is a cross-site scripting (XSS) flaw arising from improper input sanitization during web page generation in Teams for Android. An authorized attacker can inject malicious script payloads through application inputs that are rendered without proper neutralization. The attack requires the attacker to have authorized access to Teams and for a target user to view the crafted malicious content. Successful exploitation allows the attacker to perform spoofing attacks, potentially forging message origins or identities. Patches are available from Microsoft.
Affected products
- Microsoft Teams for Android <UNKNOWN>
Timeline
- 2026-08-11: disclosed