Executive brief
Microsoft Teams for Android is a widely-used messaging and collaboration app. A flaw allows an authorized attacker to extract sensitive information from the app's network communications, potentially exposing user data or credentials.
Technical details
The vulnerability is an information disclosure flaw caused by insertion of sensitive data into network communications in Microsoft Teams for Android. An authorized attacker (one with legitimate access to the application or network position) can intercept and read sensitive information transmitted by the app. The vulnerability requires either prior authorization or adjacent network access to exploit, but does not require code execution or special privileges. Patches are available through Microsoft's regular security updates.
Affected products
- Microsoft Teams for Android unspecified
Timeline
- 2026-09-08: disclosed