← Blog

EngageLab SDK: Intent Redirection Widens Android Risk

Share on X

Microsoft's spring 2026 article revisited a third-party SDK issue in EngageLab EngageSDK where an exported activity enabled intent redirection, letting rogue apps coerce partner applications into exposing privileged content-provider paths. Researchers tied the exposure footprint to tens of millions of Play installs—including a large share of cryptocurrency wallet integrations—before SDK 5.2.1 (Nov 2025) removed the risky export configuration.

The issue is materially different from a central SQL theft yet matters for consumer financial apps that inherit SDK trust boundaries.

Canonical record: EngageLab SDK issue on BreachHistory.

Sources: Microsoft Security Blog, Security Affairs