Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

GOTRAX Elo Electrical Bike: A Easy, No-Stress Method To Get Round

April 10, 2026

Right here’s What The First Yr Taught Them

April 10, 2026

TCL NXTPAPER 70 Professional Brings Paper-Like Consolation and Critical Battery Life to a Price range Cellphone You Can Seize Proper Now

April 10, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • GOTRAX Elo Electrical Bike: A Easy, No-Stress Method To Get Round
  • Right here’s What The First Yr Taught Them
  • TCL NXTPAPER 70 Professional Brings Paper-Like Consolation and Critical Battery Life to a Price range Cellphone You Can Seize Proper Now
  • Finest Credit score Playing cards for Eating in Singapore (April 2026)
  • EngageLab SDK Flaw Uncovered 50M Android Customers, Together with 30M Crypto Wallets
  • An Finish-to-Finish Coding Information to NVIDIA KVPress for Lengthy-Context LLM Inference, KV Cache Compression, and Reminiscence-Environment friendly Era
  • Razer’s new gaming earbuds include a case that pulls its weight
  • Apple will launch a brand new iPhone Air 2, irrespective of the gross sales
Friday, April 10
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - EngageLab SDK Flaw Uncovered 50M Android Customers, Together with 30M Crypto Wallets
Cybersecurity & Digital Rights

EngageLab SDK Flaw Uncovered 50M Android Customers, Together with 30M Crypto Wallets

NextTechBy NextTechApril 10, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
EngageLab SDK Flaw Uncovered 50M Android Customers, Together with 30M Crypto Wallets
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananApr 09, 2026Vulnerability / Cell Safety

Particulars have emerged a couple of now-patched safety vulnerability in a extensively used third-party Android software program growth package (SDK) known as EngageLab SDK that might have put tens of millions of cryptocurrency pockets customers at threat.

“This flaw permits apps on the identical system to bypass Android safety sandbox and acquire unauthorized entry to personal knowledge,” the Microsoft Defender Safety Analysis Crew mentioned in a report printed at the moment.

EngageLab SDK presents a push notification service, which, based on its web site, is designed to ship “well timed notifications” primarily based on person habits already tracked by builders. As soon as built-in into an app, the SDK presents a option to ship customized notifications and drive real-time engagement.

The tech big mentioned a major variety of apps utilizing the SDK are a part of the cryptocurrency and digital pockets ecosystem, and that the affected pockets apps accounted for greater than 30 million installations. When non‑pockets apps constructed on the identical SDK are included, the set up rely surpasses 50 million.

Microsoft didn’t reveal the names of the apps, however famous that each one these detected apps utilizing susceptible variations of the SDK have been faraway from the Google Play Retailer. Following accountable disclosure in April 2025, EngageLab launched model 5.2.1 in November 2025 to deal with the vulnerability.

The difficulty, recognized in model 4.5.4, has been described as an intent redirection vulnerability. Intents in Android refer to messaging objects that are used to request an motion from one other app element.

Intent redirection happens when the contents of an intent {that a} susceptible app sends are manipulated by taking benefit of its trusted context (i.e., permissions) to realize unauthorized entry to protected parts, expose delicate knowledge, or escalate privileges throughout the Android setting.

An attacker may exploit this vulnerability by means of a malicious app put in on the system via another means to entry inner directories related to an app that has the SDK built-in, leading to unauthorized entry to delicate knowledge.

There isn’t any proof that the vulnerability was ever exploited in a malicious context. That mentioned, builders who combine the SDK are beneficial to replace to the newest model as quickly as attainable, particularly on condition that even trivial flaws in upstream libraries can have cascading impacts and affect tens of millions of gadgets.

“This case exhibits how weaknesses in third‑social gathering SDKs can have massive‑scale safety implications, particularly in excessive‑worth sectors like digital asset administration,” Microsoft mentioned. “Apps more and more depend on third‑social gathering SDKs, creating massive and infrequently opaque provide‑chain dependencies. These dangers improve when integrations expose exported parts or depend on belief assumptions that aren’t validated throughout app boundaries.”

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s traits at the moment: learn extra, subscribe to our e-newsletter, and turn out to be a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Adobe Reader Zero-Day Exploited by way of Malicious PDFs Since December 2025

April 9, 2026

Risk Actors Get Artful With Emojis to Escape Detection

April 9, 2026

Niobium Introduces The Fog

April 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

GOTRAX Elo Electrical Bike: A Easy, No-Stress Method To Get Round

By NextTechApril 10, 2026

Assist CleanTechnica’s work by means of a Substack subscription or on Stripe. For those who’re…

Right here’s What The First Yr Taught Them

April 10, 2026

TCL NXTPAPER 70 Professional Brings Paper-Like Consolation and Critical Battery Life to a Price range Cellphone You Can Seize Proper Now

April 10, 2026
Top Trending

GOTRAX Elo Electrical Bike: A Easy, No-Stress Method To Get Round

By NextTechApril 10, 2026

Assist CleanTechnica’s work by means of a Substack subscription or on Stripe.…

Right here’s What The First Yr Taught Them

By NextTechApril 10, 2026

When TikTok Store launched in Spain in late 2024, most magnificence…

TCL NXTPAPER 70 Professional Brings Paper-Like Consolation and Critical Battery Life to a Price range Cellphone You Can Seize Proper Now

By NextTechApril 10, 2026

Most telephone screens merely blast gentle into your eyes for hours on…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!