← EngageLab

2026 EngageLab SDK — intent-redirection flaw risked sandbox bypass on millions of Android installs (coordinated disclosure; patched Nov 2025)

2026 50.0M records affected Share on X

Data compromised

Potential access to sandboxed partner app data reachable via abusive intents (risk scenario, not a confirmed single-database leak)

Technical writeup

Microsoft’s April 9, 2026 security blogging and downstream reporting (Security Affairs, The Hacker News) revisited coordinated disclosure work that began April 2025 against EngageLab’s EngageSDK: an exported MTCommonActivity let malicious apps coerce intent redirection, bypassing sandbox expectations and risking private content-provider data. Researchers cited more than fifty million aggregated Play installs across affected integrations and roughly thirty million wallet-oriented installs specifically. EngageLab released fixed SDK 5.2.1 on November 3, 2025, making the risky component non-exported; exploitation was not confirmed in-field in the summarized research. Distinct from a centralized database breach yet material to supply-chain confidentiality risk.

Root cause

Insecure third-party SDK exported component permitting intent redirection attacks against integrated Android apps before patch uptake

References