2026 EngageLab SDK — intent-redirection flaw risked sandbox bypass on millions of Android installs (coordinated disclosure; patched Nov 2025)
Data compromised
Potential access to sandboxed partner app data reachable via abusive intents (risk scenario, not a confirmed single-database leak)
Technical writeup
Microsoft’s April 9, 2026 security blogging and downstream reporting (Security Affairs, The Hacker News) revisited coordinated disclosure work that began April 2025 against EngageLab’s EngageSDK: an exported MTCommonActivity let malicious apps coerce intent redirection, bypassing sandbox expectations and risking private content-provider data. Researchers cited more than fifty million aggregated Play installs across affected integrations and roughly thirty million wallet-oriented installs specifically. EngageLab released fixed SDK 5.2.1 on November 3, 2025, making the risky component non-exported; exploitation was not confirmed in-field in the summarized research. Distinct from a centralized database breach yet material to supply-chain confidentiality risk.
Root cause
Insecure third-party SDK exported component permitting intent redirection attacks against integrated Android apps before patch uptake
References
- https://www.microsoft.com/en-us/security/blog/2026/04/09/intent-redirection-vulnerability-third-party-sdk-android/
- https://securityaffairs.com/190586/hacking/engagelab-sdk-flaw-opens-door-to-private-data-on-50m-android-devices.html
- https://thehackernews.com/2026/04/engagelab-sdk-flaw-exposed-50m-android.html