Microsoft's spring 2026 article revisited a third-party SDK issue in EngageLab EngageSDK where an exported activity enabled intent redirection, letting rogue apps coerce partner applications into exposing privileged content-provider paths. Researchers tied the exposure footprint to tens of millions of Play installs—including a large share of cryptocurrency wallet integrations—before SDK 5.2.1 (Nov 2025) removed the risky export configuration.
The issue is materially different from a central SQL theft yet matters for consumer financial apps that inherit SDK trust boundaries.
Canonical record: EngageLab SDK issue on BreachHistory.
Sources: Microsoft Security Blog, Security Affairs