Green Google Androd robots with one Red Robot signifying danter

Android Wallet Apps Got Burned by Someone Else’s SDK

A flawed third-party SDK impacted over 50 million Android app installations, exposing users to significant data leakage risks.

A third-party SDK is to blame for Android wallet app turned into a security risk, impacting over 50 million app installations.

In a Thursday post by the Microsoft Defender Security Research Team, the report revealed the flawed Android SDK was used in the third-party Android library called EngageSDK. The library allows developers to add messaging and push-notification to their wallet apps. Microsoft said apps using the library exposed users to data leakage of PII, such as user credentials and financial data.

Impacted, researchers said, were crypto wallet apps, representing 30 million app downloads, and 20 million additional non‑wallet apps built on the same SDK. Microsoft did not identify any of the affected apps by name adding vulnerable app versions were removed from Google Play.

Affected apps were patched via an SDK update from EngageLab to version 5.2.1. In the report the SDK fix is branded as EngageLab, which is part of Aurora Mobile – a China-based ’s push notification services, claiming to serve over 600,000 businesses and developers.

Microsoft said the bug is classified as an intent redirection flaw, allowing the app with the flawed SDK to abuse the trusted permissions of other apps on the same Android device. “In the fixed version, the vulnerable activity is set to non-exported, which prevents it from being invoked by other apps,” Microsoft wrote.

Researchers reported the flaw in April 2025 and fixed on Nov. 3, 2025. Technically, an eight-month window existed between Microsoft’s initial report to EngageLab and the release of the patched SDK version 5.2.1. However, Microsoft reported that Google was able to protect app users even before the official fix was finalized. According to Microsoft, the Android Security Team activated its Google Play Protect security platform and “mitigated the specific EngageSDK risks” by identifying and blocking the malicious “intents” that would have triggered the vulnerability ahead of the official fix.

The bigger story is not the EngageSDK flaw. It’s the software supply chain. Microsoft’s finding underscores how one flaw in a trusted SDK can spread risk across 50 millions installs. That’s a familiar story repeated in recent attacks on Axios and AppsFlyer where the danger is not the app itself, but the code it quietly pulls in.

Additional research to this Microsoft team report is credited to Dimitrios Valsamaras and other members of Microsoft Threat Intelligence, according to the post.

Image by neo tam from Pixabay

Total
0
Shares
Previous Article
Cracked AI microchip with an orange warning triangle and glowing edges on a circuit board

PraisonAI Framework Bug: Latest Example of ‘Agentic AI Security Crisis’

Next Article
Old button interface for industrial controls seen on rusty console

Modbus: Still Running. Still a Problem.

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading