Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Razer Hammerhead V3 HyperSpeed Wi-fi Earbuds Pack Focused Upgrades for Avid gamers Who Change Gadgets Typically

April 10, 2026

How cities can put together to beat FIFA World Cup transportation hurdles

April 10, 2026

HONEYWELL TO HELP BOOST FUEL PRODUCTION AND ENHANCE WORKFORCE CAPABILITIES AT DANGOTE REFINERY

April 10, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Razer Hammerhead V3 HyperSpeed Wi-fi Earbuds Pack Focused Upgrades for Avid gamers Who Change Gadgets Typically
  • How cities can put together to beat FIFA World Cup transportation hurdles
  • HONEYWELL TO HELP BOOST FUEL PRODUCTION AND ENHANCE WORKFORCE CAPABILITIES AT DANGOTE REFINERY
  • New ultrasonic wristband tracks hand actions with precision
  • The Artemis 2 astronauts received a non-public ‘Challenge Hail Mary’ screening earlier than launch. Here is their verdict
  • 5 AI Compute Architectures Each Engineer Ought to Know: CPUs, GPUs, TPUs, NPUs, and LPUs In contrast
  • Modern Wristband Makes use of Sound Waves to Observe Each Hand Movement and Direct Robotic Palms Wirelessly
  • What founders can be taught from Anjuna’s layoffs and restoration
Friday, April 10
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - EngageLab SDK Flaw Uncovered 50M Android Customers, Together with 30M Crypto Wallets
Cybersecurity & Digital Rights

EngageLab SDK Flaw Uncovered 50M Android Customers, Together with 30M Crypto Wallets

NextTechBy NextTechApril 10, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
EngageLab SDK Flaw Uncovered 50M Android Customers, Together with 30M Crypto Wallets
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananApr 09, 2026Vulnerability / Cell Safety

Particulars have emerged a couple of now-patched safety vulnerability in a extensively used third-party Android software program growth package (SDK) known as EngageLab SDK that might have put tens of millions of cryptocurrency pockets customers at threat.

“This flaw permits apps on the identical system to bypass Android safety sandbox and acquire unauthorized entry to personal knowledge,” the Microsoft Defender Safety Analysis Crew mentioned in a report printed at the moment.

EngageLab SDK presents a push notification service, which, based on its web site, is designed to ship “well timed notifications” primarily based on person habits already tracked by builders. As soon as built-in into an app, the SDK presents a option to ship customized notifications and drive real-time engagement.

The tech big mentioned a major variety of apps utilizing the SDK are a part of the cryptocurrency and digital pockets ecosystem, and that the affected pockets apps accounted for greater than 30 million installations. When non‑pockets apps constructed on the identical SDK are included, the set up rely surpasses 50 million.

Microsoft didn’t reveal the names of the apps, however famous that each one these detected apps utilizing susceptible variations of the SDK have been faraway from the Google Play Retailer. Following accountable disclosure in April 2025, EngageLab launched model 5.2.1 in November 2025 to deal with the vulnerability.

The difficulty, recognized in model 4.5.4, has been described as an intent redirection vulnerability. Intents in Android refer to messaging objects that are used to request an motion from one other app element.

Intent redirection happens when the contents of an intent {that a} susceptible app sends are manipulated by taking benefit of its trusted context (i.e., permissions) to realize unauthorized entry to protected parts, expose delicate knowledge, or escalate privileges throughout the Android setting.

An attacker may exploit this vulnerability by means of a malicious app put in on the system via another means to entry inner directories related to an app that has the SDK built-in, leading to unauthorized entry to delicate knowledge.

There isn’t any proof that the vulnerability was ever exploited in a malicious context. That mentioned, builders who combine the SDK are beneficial to replace to the newest model as quickly as attainable, particularly on condition that even trivial flaws in upstream libraries can have cascading impacts and affect tens of millions of gadgets.

“This case exhibits how weaknesses in third‑social gathering SDKs can have massive‑scale safety implications, particularly in excessive‑worth sectors like digital asset administration,” Microsoft mentioned. “Apps more and more depend on third‑social gathering SDKs, creating massive and infrequently opaque provide‑chain dependencies. These dangers improve when integrations expose exported parts or depend on belief assumptions that aren’t validated throughout app boundaries.”

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s traits at the moment: learn extra, subscribe to our e-newsletter, and turn out to be a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Adobe Reader Zero-Day Exploited by way of Malicious PDFs Since December 2025

April 9, 2026

Risk Actors Get Artful With Emojis to Escape Detection

April 9, 2026

Niobium Introduces The Fog

April 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

Razer Hammerhead V3 HyperSpeed Wi-fi Earbuds Pack Focused Upgrades for Avid gamers Who Change Gadgets Typically

By NextTechApril 10, 2026

Razer launched the Hammerhead V3 HyperSpeed wi-fi earbuds at the moment, and it’s clearly a…

How cities can put together to beat FIFA World Cup transportation hurdles

April 10, 2026

HONEYWELL TO HELP BOOST FUEL PRODUCTION AND ENHANCE WORKFORCE CAPABILITIES AT DANGOTE REFINERY

April 10, 2026
Top Trending

Razer Hammerhead V3 HyperSpeed Wi-fi Earbuds Pack Focused Upgrades for Avid gamers Who Change Gadgets Typically

By NextTechApril 10, 2026

Razer launched the Hammerhead V3 HyperSpeed wi-fi earbuds at the moment, and…

How cities can put together to beat FIFA World Cup transportation hurdles

By NextTechApril 10, 2026

Three transit specialists provide suggestions for public transit, site visitors congestion and…

HONEYWELL TO HELP BOOST FUEL PRODUCTION AND ENHANCE WORKFORCE CAPABILITIES AT DANGOTE REFINERY

By NextTechApril 10, 2026

Digital course of and automation applied sciences will assist Africa’s largest refinery…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!